11-19-2018 07:54 AM - edited 02-21-2020 08:29 AM
Hi,
I'm working with a new FTD HA-setup (Firepower 21x0) that will replace an old ASA-pair. We plan on running the latest 6.2.3.x-patch.
The FTD will handle internal traffic only (another FTD HA pair is handling Internet/WAN-traffic). However, the FTD will handle traffic for a 24/7 live production network with time-critical sensitive applications/protocols.
I have a big question in my mind as to how to best handle IPS Rule Updates that cause SNORT Service Interruptions in this environment. The customer wants to have IPS active to gain visibility, but they do not want the SNORT service interruptions for sensitive flows.
I believe I can work-around this problem by preparing Fastpath Pre-filter rules that can be enabled before the customer wants to do a manual Rule Update. This way critical traffic could be manually excluded from the SNORT Service Interruption (I've also looked at "snort preserve-connection" as an option but this only preserves existing flows, not new ones).
My question bottles down to how often we would recommend installing Rule Updates in an environment such as this. As the Rule Update will be a manual procedure I expect the customer does not want to do it every day/every week.
Considering this FTD will only handle internal traffic, how often would be best practise to do a manual Rule Update?
Would the customer miss out on a lot of features if they only did it once a month? Once a quarter?
Thanks,
Regards,
Erik
11-19-2018 09:12 AM
Hi @ejans,
Nice question you have there.
Nothing we can do since it is the behavior of the SNORT process when deploying the policy with the updated intrusion rules but I would recommend to pick a day every week which you think it has a less transactions happening (e.g. weekend night).
Thanks
11-19-2018 09:42 AM
11-19-2018 11:13 AM
Hi @ejans,
Question, in terms of the IPS capability do you need to monitor it only or you also need proactively drop the traffic once intrusion is detected?
Thanks
11-26-2018 01:24 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide