05-28-2025 10:14 AM - edited 05-28-2025 10:15 AM
Hello, I can not find an answer to this anywhere online. It would seem self-explanatory, but apparently it's not. What encompasses the "Snort - Denied Flows" that can be seen for the FTD in FMC's Health Monitor? The numbers I am seeing in the "Snort - Denied Flow" section do not match the number of IPS/SI blocks logged. In fact, the are no IPS rule or SI blocks happening (and I am somewhat certain of this because I log them all) but the Snort - Denied Flow stats go up and down all day. What other events contribute to Snort denied flows that would be show on this graph? Any insight is appreciated. Thanks!
05-28-2025 11:01 AM
You are correct - I have asked myself the same question. To me it looks like all that is blocked by ACL is also reported blocked by Snort - especially if you have GeoBlock( after the Geolocation block is activated all ACLs (below the GeoBlock ACL) have no hit counts as they are Snort blocked).
It will be interesting to find out more about this behavior?
06-12-2025 07:54 AM
@ivanzrv Thank you for that idea. I had not considered geoblocks so you might be on to something. Unfortunately, it seems no one knows of sure!
06-21-2025 07:03 AM
Are you sure there are no SI config at all?
MHM
06-23-2025 03:15 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide