Dear,
We have a ASA FirePOWER with module sfr in monitor state "sfr fail-open monitor-only", integrate to FMC.
My query is, as long as I keep the "monitor-only" on the ASA, will any modification that I make in the FMC not impact the traffic? either create zones in the FMC, or put an instrusion policy in inline.
This I consult since I need to create an instrusion policy to see if there would be false positives, for that I will keep the monitor-only and the INStrusion policy in the IPS will put it inline.
Thanks vey much.