cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1513
Views
0
Helpful
3
Replies

FirePOWER not blocking while pruning?

Peter Koltl
Level 7
Level 7

I have found some events of type Would have dropped in ASA-Firepower FMC logs. The guide explains

The event type is always Would have dropped for packets seen while the system is pruning, regardless of deployment.

[...]

 the system sometimes prunes older event details to manage disk space usage.

The module is inline and IPS policy is set to Drop when Inline so I can think of no other explanation.

Would Firepower really pass traffic matching a threat pattern while it is busy pruning?? Were these packets really not dropped?

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

I would like to know the answer to that question as well. Peter, were you able to find anything about this?

Thanks!

Neno

Thank you for rating helpful posts!

Peter Koltl
Level 7
Level 7

No findings yet, Neno. Sorry.

Peter, 

Were you able to find any such information for your query?

 

Review Cisco Networking for a $25 gift card