07-18-2019 08:54 PM - edited 02-21-2020 09:19 AM
Hi,
Does any one here have experience on the firepower, the results on the intrusion events have "would have dropped" and "drop"? One IPS signature but two results drop and would have dropped.
the firepower are configured on inline mode. Any one here have the same experience? How did you manage to configure the FMC?
software version = 6.2.3 both fmc and sensor.
Thanks in advance.
07-19-2019 10:10 AM
as long as your FMC is configured to drop in line it will drop the packet and log it in the event logs.
07-19-2019 10:44 PM
It should work as you said, but I've seen cases where http and https traffic to the same host fires the same ips rule, but http traffic gets dropped and https traffic gets would have dropped.
Don't know if it depends on the host not fully discovered or what, but I've seen it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide