ā01-30-2023 06:47 AM
Hello,
I understand that in Access Control rules on the FTD, there are "block" and "block with reset" actions, but how does one configure Snort / IPS to send a RST if it's dropping something (traffic that was set to "allow" in the ACP?) Furthermore, if possible, is it or can it be so granular as to allow for the specifying interfaces, zones, or the like?
Long story short, without all of the details, we are doing some testing... When moving a test malware file from zone to another, that is allowed by the ACP, the IPS is dropping the traffic as expected. The lack of a RST is causing the internal process that is moving the file to hang until it times out. I would like to send a RST in this case, but not for something being inspected from the internet. Is it possible?
Thanks!
Solved! Go to Solution.
ā02-01-2023 12:40 PM
https://rayka-co.com/lesson/firepower-malware-and-file-policy/
check the reset connection in this above link
ā02-01-2023 02:13 PM
If you create a Malware & File policy you can select drop with an option to reset. The Intrusion policy however does not have an option to reset when traffic is blocked.
This is a screenshot from the Malware & File policy when adding a rule:
ā02-01-2023 12:07 PM
Does anyone have any insight on this? I can find no documentation. Obviously, if it was an access rule dropping the traffic, one could use "Drop with reset" but this is being dropped by IPS. I can find no information or documentation online about sending a RST. I would imagine is has to be possible somehow? Thanks!
ā02-01-2023 12:10 PM
the Snort not drop traffic is send verdict to Lina, Lina will drop the traffic.
ā02-01-2023 12:31 PM
ā02-01-2023 12:40 PM
https://rayka-co.com/lesson/firepower-malware-and-file-policy/
check the reset connection in this above link
ā02-01-2023 02:13 PM
If you create a Malware & File policy you can select drop with an option to reset. The Intrusion policy however does not have an option to reset when traffic is blocked.
This is a screenshot from the Malware & File policy when adding a rule:
ā02-02-2023 05:21 AM
ā02-02-2023 06:48 AM
ā02-02-2023 07:33 AM
Your understanding is correct.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide