03-16-2021 11:22 PM
Hi teams,
I'm a beginner of Cisco firepower!
I have some questions!
I have no idea about preprocessor!
As to my knowledge, preprocessor is a plug-in of SNORT engine.
When LINA engine pass the packet, preprocessor get that packet.
Next, preprocessor deal with the packet whether pass or not.
In this progress,I don't know role of preprocessor.
Plus, If I have to optimize the intrusion rule, how can I address some rules related preprocessor like GID 124, or 125 etc?
Thank you.
Solved! Go to Solution.
03-17-2021 06:39 AM - edited 03-17-2021 06:39 AM
I would also refer you to Cisco Live presentation BRKSEC-3300. In it, the author explains the role of the preprocessors in your Network Analysis Policy and how/why you may want to tune them.
03-17-2021 12:09 AM
First, i would suggest reading these flows so you can understand the flows and how they go each level and let us know what device is this? Firepower or ASA with SFR Module?
03-17-2021 06:39 AM - edited 03-17-2021 06:39 AM
I would also refer you to Cisco Live presentation BRKSEC-3300. In it, the author explains the role of the preprocessors in your Network Analysis Policy and how/why you may want to tune them.
03-22-2021
07:23 PM
- last edited on
03-09-2022
11:15 PM
by
smallbusiness
Thank you for your reply!
There is no contents that I wants in the video.
But, It covers the overall thing about firepower. It's very useful information!
Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide