cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1301
Views
0
Helpful
1
Replies

SourceFire 3D8250 : Network Disruption while adding Access control policy

stuartgeddes
Level 1
Level 1

Hi guys,

I am managing 4 IPS 3D8250s using FireSight. I moved all the IPS appliances from default access control policy to a custom Access control policy. While moving the appliances to this policy ( adding the appliances under the tab "Targets" and by clicking "save and apply") I lose access to the network. The outage is around 5-10 mins. Is this a normal behavior ?? 

The IPS appliances are configured as L2 fail-open. All the traffic passes through these Appliances.

IPS : SourceFire 3D8250
Version : 5.3.0.3

FireSight : Defense Center 1500
Version : 5.3.1.1

Appreciate your help !!

Thanks and Regards,
Stuart

1 Reply 1

vrgaikwad
Level 1
Level 1

Hi Stuartgeddes,

Normally there wont be any network outage due to access control policy installation but during policy installation sourcefire appliances do not inspect the traffic and bypass it but I have not observed network outage. I have heard that Firewall Fail-over can happened due to Access control policy installation if your sensor is directly connected to firewall. Due to load Defense center console can become unresponsive for some time.
 

 

Review Cisco Networking for a $25 gift card