Good morning:
I have a port mirror on an interface.
This traffic is causing intrusion events.
How can I filter them?
I've tried putting this traffic in a trust rule in the access control policy, but it doesn't work.
I've also tried putting it in a prefilter, but that didn't work either.
Any ideas?