A work around was to place a Prefilter this way it doesn't reach snort, and traffic will pass. I was affected with this with Anyconnect fulltunnel ( no split tunnel). Users were no able to use internet. After the pre-filter everything work as expecte...