Cisco Cisco Firepower Management Center 4000
20-15
FireSIGHT System User Guide
Chapter 20 Configuring Intrusion Policies
Setting Drop Behavior in an Inline Deployment
Tip
The event type is always
Would have dropped
for packets seen while the system is pruning, regardless of
deployment.
The following table summarizes drop rule behavior in passive and inline deployments.
Note that setting what is called a pass rule to Generate Events has a different effect. For information, see
Note also that your inline intrusion policies can include rules that use the
replace
keyword. For
information, see
.
To set the drop behavior of your intrusion policy:
Access:
Admin/Intrusion Admin
Step 1
Select
Policies > Intrusion > Intrusion Policy
.
The Intrusion Policy page appears.
Step 2
Click the edit icon (
) next to the policy you want to edit.
If you have unsaved changes in another policy, click
OK
to discard those changes and continue. See
for information on saving unsaved changes in another
policy.
The Policy Information page appears.
Step 3
Specify whether you want the system to drop the packet and generate an event when the packet triggers
a rule set to Drop and Generate Events in an inline deployment:
a rule set to Drop and Generate Events in an inline deployment:
•
To drop the packet and generate an event, select the
Drop when Inline
check box.
•
To generate an event but not drop the packet, clear the
Drop when Inline
check box.
Note that the system does not drop packets in a passive deployment, including when an inline interface
is in tap mode, regardless of the rule state or the inline drop behavior of the intrusion policy. For more
information, see
is in tap mode, regardless of the rule state or the inline drop behavior of the intrusion policy. For more
information, see
,
, and
Tip
On 3D9900 and Series 3 devices, an inline set can use tap mode, which allows you to passively monitor
traffic.
traffic.
Table 20-5
Drop Rule Behavior
When the deployment
is...
is...
And Drop when Inline
is...
is...
Offending packets
are...
are...
And the event type is...
inline
enabled
dropped
Dropped
inline
disabled
not dropped
Would have dropped
inline (tap mode)
enabled
not dropped
Would have dropped
inline (tap mode)
disabled
not dropped
Would have dropped
passive
enabled
not dropped
Would have dropped
passive
disabled
not dropped
Would have dropped