cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1358
Views
0
Helpful
1
Replies

Sourcefire Network Exclusion

allensurface
Level 4
Level 4

Can you exclude network traffic from being processed by the sensor so that it doesn't impact the load on the appliance? For example, if you have an 5G appliance with 10G ports inline with a network and you want to only process certain traffic. Can you have10Gig of traffic with 5Gigs of unmonitored traffic go through the box and not have it impact the performance? 

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Put the networks you don't want to inspect into a "trusted" object and set your access control policy to trust traffic from it. That will keep the sensor from inspecting that traffic.

We do this, for instance, with high volume backup traffic that transits the IPS en route to an off-site backup or replication destination.

Review Cisco Networking for a $25 gift card