04-30-2024 08:22 AM - edited 04-30-2024 08:25 AM
FTD 1140
interface configured as "passive",
access rule "passive" (configured per FTD configuration guide to set hardware interface passive)
Connected to SPAN port (span port verified functional from laptop)
From the firewall perspective, it appears that no traffic is reaching the interface, logging etc is enabled. No hit counts on the access rule.
anyone seen this ? odd that I am having issues with such a minor config... might be missing something / sw bug
Solved! Go to Solution.
04-30-2024 10:21 AM
The FTD interface i was trying to use did not release the IP assigned when it was L3 - Remains showing as a "passive interface" in the GUI - but CLI shows the interface is not passive, still set to L3
possibly a bug.
04-30-2024 08:41 AM
04-30-2024 08:56 AM
Creating a passive interface is not sufficient for populating the dashboards with information about the traffic seen on the interface. You must also do the following. The use case covers these steps. See How to Passively Monitor the Traffic on a Network.
Create a passive security zone and add the interface to it. See Configuring Security Zones.
Create access control rules that use the passive security zone as the source zone. Typically, you would apply intrusion policies in these rules to implement IDS (intrusion detection system) monitoring. See Configuring the Access Control Policy.
04-30-2024 10:21 AM
The FTD interface i was trying to use did not release the IP assigned when it was L3 - Remains showing as a "passive interface" in the GUI - but CLI shows the interface is not passive, still set to L3
possibly a bug.
04-30-2024 10:54 AM
glad all good, by the what version of code running on the device ?
04-30-2024 11:24 AM
7.2.5 (Build 208)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide