cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
260
Views
0
Helpful
6
Replies

FTD - 7.6.2 - Snort Fail Open?

Ralphy006
Level 1
Level 1

The FTD's (managed by FMC) used to drop traffic all the time when doing policy deploys. But it seems to be better in 7.x.

We have some critical network traffic flowing through the firewall. At times we do see traffic disrupted during policy deploys. I believe this is due to the snort process restarting. Is there any way to make it so traffic is NEVER disrupted even when snort needs to restart? Like a fail open?

I'm looking for any tips or setting changes to ensure traffic stays up. Thanks!

6 Replies 6

I'm not aware of any. If the policy deploy requires a service restart, that's a fact of life.

Is this common among other firewall vendors too? Personally, I feel it's unacceptable to have no workaround

Yes very common. All major firewall vendors have "scheduled deploy" features for this exact reason (among others).

balaji.bandi
Hall of Fame
Hall of Fame

yeah that's what I was reading too. Looks line "inline" ports has a fail open option. I'm not sure how many FTD users use the "inline" feature. I'd think most used routed interfaces. In which there is no option but to drop traffic which is a shame. I was hoping there was some workaround

May cisco working on that i guess - but not that i am aware any version yet. even FMC you do not have multi user policy change (unlike other vendor - just to mentioned) - some limitation, But cisco BU look this and make use case to add features.

so suggestion is do the changes in maintenance window, like off peak ours.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card