cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2032
Views
0
Helpful
2
Replies

firepower inline normalization

saintlan1
Level 1
Level 1

Hi,

 

Does any one here have experience on the firepower, the results on the intrusion events have "would have dropped" and "drop"? One IPS signature but two results drop and would have dropped.

 

the firepower are configured on inline mode. Any one here have the same experience? How did you manage to configure the FMC?

 

software version = 6.2.3 both fmc and sensor.

 

Thanks in advance.

 

2 Replies 2

as long as your FMC is configured to drop in line it will drop the packet and log it in the event logs.

please do not forget to rate.

It should work as you said, but I've seen cases where http and https traffic to the same host fires the same ips rule, but http traffic gets dropped and https traffic gets would have dropped.

Don't know if it depends on the host not fully discovered or what, but I've seen it.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card