10-01-2018 09:54 PM - edited 03-12-2019 07:00 AM
Hi, I want to restart my SNORT process, will it drop traffic? Is there any way to restart SNORT without any dropping of traffic? Thanks
10-01-2018 11:45 PM
A snort restart will typically interrupt active flows.
Here's how to do it from the sensor cli (FTD running on a Firepower appliance in this case):
> expert admin@fw1:~$ sudo su Password: root@fw1:/home/admin# pmtool restartbytype snort ? root@fw1:/home/admin# pmtool | grep snort
10-02-2018 12:38 AM
thanks @Marvin Rhoads, is there any other ways to do it without any interruption?
10-02-2018 12:49 AM
There is an option available as of Firepower 6.2.0.2 and 6.2.3 that changed the previous default behavior.
configure snort preserve-connection enable
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide