Cisco Cisco Firepower Management Center 4000

Page of 1844
 
20-15
FireSIGHT System User Guide
 
Chapter 20      Configuring Intrusion Policies
  Setting Drop Behavior in an Inline Deployment
Tip
The event type is always 
Would have dropped
 for packets seen while the system is pruning, regardless of 
deployment.
The following table summarizes drop rule behavior in passive and inline deployments.
Note that setting what is called a pass rule to Generate Events has a different effect. For information, see 
Note also that your inline intrusion policies can include rules that use the 
replace
 keyword. For 
information, see 
.
To set the drop behavior of your intrusion policy:
Access: 
Admin/Intrusion Admin
Step 1
Select 
Policies > Intrusion > Intrusion Policy
.
The Intrusion Policy page appears.
Step 2
Click the edit icon (
) next to the policy you want to edit.
If you have unsaved changes in another policy, click 
OK
 to discard those changes and continue. See 
 for information on saving unsaved changes in another 
policy.
The Policy Information page appears.
Step 3
Specify whether you want the system to drop the packet and generate an event when the packet triggers 
a rule set to Drop and Generate Events in an inline deployment:
  •
To drop the packet and generate an event, select the 
Drop when Inline
 check box.
  •
To generate an event but not drop the packet, clear the 
Drop when Inline
 check box.
Note that the system does not drop packets in a passive deployment, including when an inline interface 
is in tap mode, regardless of the rule state or the inline drop behavior of the intrusion policy. For more 
information, see 
, and 
Tip
On 3D9900 and Series 3 devices, an inline set can use tap mode, which allows you to passively monitor 
traffic.
Table 20-5
Drop Rule Behavior 
When the deployment 
is...
And Drop when Inline 
is...
Offending packets 
are...
And the event type is...
inline
enabled
dropped
Dropped
inline
disabled
not dropped
Would have dropped
inline (tap mode)
enabled
not dropped
Would have dropped
inline (tap mode)
disabled
not dropped
Would have dropped
passive
enabled
not dropped
Would have dropped
passive
disabled
not dropped
Would have dropped