cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1654
Views
0
Helpful
1
Replies

Does SNORT drop traffic, when its restarted with "Inspect Traffic During Policy Apply" is enabled in the Access Control Policy?

Joshua.Dixon
Level 1
Level 1

OK, So here is what I found on the subject.  The teacher in the instruction video states that SNORT drops traffic with this feature enabled AND SNORT restarts.  My question is, is traffic dropped?  

Here's what I found

Access Control Policy in question:

Inspect traffic during policy apply = Yes

Resource: Configuration Guide for 6.0.1

Snort® Restarts During Configuration Deployment:

The Inspect traffic during policy apply advanced access control policy general setting allows you to inspect

traffic while deploying configuration changes unless a configuration that you deploy requires the Snort process

to restart, as follows:

• Enabled — Certain configurations can require the Snort process to restart.

When the configurations you deploy do not require a Snort restart, the system initially uses the currently

deployed access control policy to inspect traffic, and switches during deployment to the access control

policy you are deploying.

• Disabled — The Snort process always restarts when you deploy. Traffic is not inspected during the

deployment.

Page: 271


Resource: Youtube

Video Title: Cisco FirePOWER Access Control Policies - Todd Lammle Training Series

Time mentioned: 15:34

Reference Link: https://youtu.be/kCZQrAYdrFo

Note: The Configuration Guide does not state that restarting SNORT will drop traffic, if "Inspect Traffic during policy

apply" is set to enabled.

1 Reply 1

Joshua.Dixon
Level 1
Level 1

To inspect traffic when you deploy configuration changes unless specific configurations require restarting the Snort process, ensure that Inspect traffic during policy apply is set to its default value (enabled). When this option is enabled, resource demands could result in a small number of packets dropping without inspection. See Snort® Restarts During Configuration Deployment for more information.


Caution


Disabling Inspect traffic during policy apply restarts the Snort process when you deploy configuration changes.


Answered my own question.  It does

Review Cisco Networking for a $25 gift card