08-22-2022 12:59 PM
We switched (pure routing changes) from a pair of ASA5585 to FP4115 v7.0.2 w/ Snort 3, everything was running fine and then all of sudden nothing can pass through FTD. FTD syslog is normal, ASP drop is normal.
We do find that the Snort has been restarted over 100 times when this issue surfaced, and we have to switch back ASA5585.
Has anyone experienced the similar issue on FTD? We have no clue at this moment. Thanks.
Leo
08-22-2022 01:17 PM - edited 08-22-2022 01:19 PM
if all traffic pass through snort then this can happened,
try config Prefilter ACL which make elephant traffic to bypass the Snort
https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200420-Processing-of-Single-Stream-Large-Sessio.html
08-22-2022 01:45 PM
We have had similar issues with all our client's FTDs after upgrading to 7.0.x. TAC says this is a bug, and that upgrading to 7.1 or greater resolves the issue. Stability wise I think 7.2 is better. Though we do not have any FTDs running this code yet, I have not heard of many big issues with it yet.
08-22-2022 02:33 PM
Thanks, can you send me the bug id?
Leo
08-22-2022 02:37 PM
unfortunately I do not have the bug ID as I was not the engineer working with TAC.
08-22-2022 11:12 PM
Suspecting the below bug. that is fix in 7.1
ssl traffic dropped by FTD while CH packet has a destination port no greater than source port |
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide