This article aims at addressing a problem wherein snort may cause connection failures without dropping any traffic due to some snort rules
Snort cause connection failures for rules with "replace" keyword even if the rule state is set to "Generate Events".
The reason is, currently snort does not look at the rule state before enforcing the "replace" action, as a result if a rule state says "generate events", snort will still modify the packet and cause connection failures.
An enhancement request has been opened to change this behavior
If you want to enable the above rules to only alert and not cause traffic failures, the only workaround available right now is to clone a local rule of the original rule and remove the "replace" keyword and enable this local rule instead of the rule provided by Sourcefire.
Please note: Removing the replace keyword may limit the effectiveness of the rule
Hi Guys, just want to double check with you. In FTD, I have 2 subnet and if I need to have intervlan for those 2 VLAN, do I still need to configure an identity NAT or any NAT?My target is doing intervlan routing between the 2 VLAN without any IP change.th...
Hi,I set up DVTI in EVE with 2 routers. HUB------SPOKE.Virtual-template is not showing up/down. Instead of up/up.Checked Phase1 and Phase2 parameters but not sure where I made a mistake.Attached diagram and configuration.Please take a look.
I tested using both Cisco ISE 2.4 (patch 9) and Cisco ISE 2.6 (patch 1). I have a user who successfully authenticated via RADIUS against ISE. Under ISE, Operations > Live Logs (and Live sessions), I see the user authenticated. After the accounting requ...