cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
353
Views
1
Helpful
1
Replies

Firepower Prefilter tunneled traffic

cpaquet
Level 1
Level 1

I was asked the following question.  I think I know the answer, but would like to validate it.

=======

Question: How many levels down of traffic tagged as tunneled by the prefilter can the Snort Engine analyze?

=======

If traffic is identified as 'Tunneled' in the prefilter, LINA will tag that traffic for the Snort Engine to take a deeper look: to analyze let's say not only the GRE session, but also the tunneled session. 

What about if the traffic is BGP over GRE over GRE?   [Why would you want to do this?  I don't have a practical example, but regardless, the question is valid].  

I suspect that the Snort engine seeing only 1 tunneled tag with only look at one level down.  But I would like to get a confirmation on this. 

Thanks.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

AFAIK, it's just one level down as you surmised.

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

AFAIK, it's just one level down as you surmised.

Review Cisco Networking for a $25 gift card