cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
497
Views
0
Helpful
1
Replies

Question about Trust and SI in FTD

FredrikW73
Level 1
Level 1

You can Trust traffic in the Access Controll Policy rather than Allowing it.

Is trusted traffic still subject to Security Intelligence checks and blocking?

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes it is - SI checks come before the ACP in the order of operations. Only if you fastpath the traffic in your preflter policy would it skip SI (and indeed all of the Snort subsystem).

FTD OOO - Nazmul.PNG

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes it is - SI checks come before the ACP in the order of operations. Only if you fastpath the traffic in your preflter policy would it skip SI (and indeed all of the Snort subsystem).

FTD OOO - Nazmul.PNG

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card