05-11-2017 08:37 AM - edited 02-21-2020 06:04 AM
OK, So here is what I found on the subject. The teacher in the instruction video states that SNORT drops traffic with this feature enabled AND SNORT restarts. My question is, is traffic dropped?
Here's what I found
Access Control Policy in question:
Inspect traffic during policy apply = Yes
Resource: Configuration Guide for 6.0.1
Snort® Restarts During Configuration Deployment:
The Inspect traffic during policy apply advanced access control policy general setting allows you to inspect
traffic while deploying configuration changes unless a configuration that you deploy requires the Snort process
to restart, as follows:
• Enabled — Certain configurations can require the Snort process to restart.
When the configurations you deploy do not require a Snort restart, the system initially uses the currently
deployed access control policy to inspect traffic, and switches during deployment to the access control
policy you are deploying.
• Disabled — The Snort process always restarts when you deploy. Traffic is not inspected during the
deployment.
Page: 271
Resource: Youtube
Video Title: Cisco FirePOWER Access Control Policies - Todd Lammle Training Series
Time mentioned: 15:34
Reference Link: https://youtu.be/kCZQrAYdrFo
Note: The Configuration Guide does not state that restarting SNORT will drop traffic, if "Inspect Traffic during policy
apply" is set to enabled.
05-11-2017 10:11 AM
To inspect traffic when you deploy configuration changes unless specific configurations require restarting the Snort process, ensure that Inspect traffic during policy apply is set to its default value (enabled). When this option is enabled, resource demands could result in a small number of packets dropping without inspection. See Snort® Restarts During Configuration Deployment for more information.
![]() Caution |
Disabling Inspect traffic during policy apply restarts the Snort process when you deploy configuration changes. |
Answered my own question. It does
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide