11-27-2016 09:46 PM - edited 03-12-2019 06:12 AM
Hello,
I have confusing now what should be correct order of data inspection under firepower.
With reference to information:
My understand packet will going thru like following but few components I have mess up now.
- Intrusion policy used before access control rule is determined
- Default network analysis policy
- Default Access control policy
- Security Intelligence
- Default action policy
Could anyone can explain more clear?
Thanks!
11-28-2016 11:08 AM
Traffic is being processed in two steps
Step 01: Pre-processing
Step 02: Access-Control Policy
Let me know if that answers your question. In case you want to know anything more specific about any step let me know.
11-28-2016 06:58 PM
11-29-2016 09:04 AM
The network discovery policy is used to detect applications (using open-app-id), hosts (using traffic analysis + active checks using nmap) and identity discovery (using traffic analysis of http/ftp/etc. (identity using agent/pxgrid not included)
Considering "Intrusion Policy used before Access Control rule is determined"
A default intrusion prevention policy can be applied that is used before access-control-policy rules. Since many rules like url-filtering need to see the payload to determine if traffic is allowed, an ips policy can be applied to check traffic that is initially allowed to check if a access control policy rule matches.
Considering "Default Network Analysis Policy"
The default network analysis policy is used if no other network-analysis rules are matched. Network analysis policy is used to pre-process traffic (normalization).
Traffic flow:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide