cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1490
Views
0
Helpful
6
Replies

SNORT allow/disallow traffic flow when Snort is busy or unavailable

ida71
Level 1
Level 1

Hi All,

 

I'm suffering form brain fade. I'm sure there is a setting for this on the FMC, but for the life of me I can't find it at the moment.

It's running V7.0.1.

Default is to block traffic, but we have an issue with Snort crapping out randomly and exhausting the 1550 memory Blocks.

show blocks  will get this for you.

 

Anyone know where that setting is, so I can change it to allow so if Snort craps out again, whilst TAC are trying to diagnose it, the customers will still get served.

 

Thanks

6 Replies 6

ida71
Level 1
Level 1

I think have found the answer. When I first used FTD's a few years back it was as inline IPS & that setting existed in the interface configuration. Looks like it does NOT exist in routed FW mode

 

If anyone knows better, please share.

Marvin Rhoads
Hall of Fame
Hall of Fame

New connections will not be established when Snort is unavailable (unless of course they are fastpathed via prefilter policy).

If Snort goes down (or restarts as part of a deployment, for example), existing connections should continue to be allowed by default.

https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/policy_management.html#concept_uc1_gtq_ty

Snort is crapping out by itself, no policy deploy etc. Fully aware of the Snort traffic interrupts when Snort restarts.

We have an issue where Snort craps out on Active FW, but process is still running so FW's do NOT failover, manual failover & restart of Snort on the now Standby FW resolves the issue. To improve the customer experience, I was looking for the setting to allow traffic flow based on ACL's only if Snort fails, which does exist for inline interfaces used as IPS.

Thanks Marvin, appreciate the feedback.
Chris.

ida71
Level 1
Level 1

Hi Marvin,, not sure what's up with the link you posted but it goes to

https://spotler.e-druva.com/<SNIP>   Dead link now

 

And wants to unsubscribe you !

Thanks for the heads up @ida71 I fixed the link. Weird - it displayed OK but did indeed have that unsubscribe link.

Review Cisco Networking for a $25 gift card