05-11-2020 03:03 AM - edited 05-11-2020 03:28 AM
I've got a firepower going. The policy has pure access rules.
Now I have a very high CPU load with active traffic.
See pictures
What I do not understand is why SNORT has so much CPU.
I have pure Access Rulles and no inspection rules
When I look at the Connection Events and click on Snort ID Filter I see all the traffic
Why does he show up at Snort Modul?
05-11-2020 07:02 AM
Could you check if there is any active packet capture or debugging?
Best regards.
05-13-2020 11:08 PM
There are no active packet capture or debugging
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide