09-13-2018 07:13 AM - edited 03-12-2019 04:10 AM
If you upgrade the firepower service module while not redirecting traffic to it with the service policy, when it restarts will you get dropped packets?
Solved! Go to Solution.
09-13-2018 10:16 AM
Well, if you are not sending any traffic to firepower module from the ASA, then no impact will be there on traffic due to any activity on firepower module including a reboot on the module. So, in short no dropped packets if no traffic is redirected.
Infact this is a recommended action to either have 'fail-open' action set in policy created for Firepower on ASA or remove the redirect policy while doing any maintenance on the Firepower.
HTH
AJ
09-13-2018 10:16 AM
Well, if you are not sending any traffic to firepower module from the ASA, then no impact will be there on traffic due to any activity on firepower module including a reboot on the module. So, in short no dropped packets if no traffic is redirected.
Infact this is a recommended action to either have 'fail-open' action set in policy created for Firepower on ASA or remove the redirect policy while doing any maintenance on the Firepower.
HTH
AJ
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide