300-710 · Question #182
Refer to the exhibit. An engineer is modifying an access control policy to add a rule to inspect all DNS traffic that passes through the firewall. After making the change and deploying the policy…
The correct answer is D. The action of the rule is set to trust instead of allow. If DNS traffic is not being inspected by the Snort engine after an access control policy deployment in Cisco FTD/FMC, the problem is likely that the action of the rule configured for DNS traffic is set to 'Trust' instead of 'Allow'.
Question
Refer to the exhibit. An engineer is modifying an access control policy to add a rule to inspect all DNS traffic that passes through the firewall. After making the change and deploying the policy, they see that DNS traffic is not being inspected by the Snort engine. What is the problem?
Exhibit
Options
- AThe rule must specify the security zone that originates the traffic.
- BThe rule is configured with the wrong setting for the source port.
- CThe rule must define the source network for inspection as well as the port.
- DThe action of the rule is set to trust instead of allow.
How the community answered
(27 responses)- A7% (2)
- B4% (1)
- C11% (3)
- D78% (21)
Why each option
If DNS traffic is not being inspected by the Snort engine after an access control policy deployment in Cisco FTD/FMC, the problem is likely that the action of the rule configured for DNS traffic is set to 'Trust' instead of 'Allow'.
While specifying security zones is good practice, it would not inherently prevent Snort inspection if the traffic matches the rule otherwise and the action is 'Allow'.
The question implies the rule is for 'DNS traffic', meaning the port (53) is correctly identified; if the port were wrong, traffic would not match the rule at all, not just fail inspection.
Defining the source network is part of traffic identification for a rule, but not directly responsible for enabling Snort inspection once traffic matches a rule, as the action dictates inspection.
In Cisco FTD/FMC, an access control rule with the action 'Trust' bypasses all deeper inspection by the Snort engine, including intrusion policies, file policies, and malware inspection. For Snort inspection to occur, the rule's action must be 'Allow' (or 'Block' if inspection is followed by a block).
Concept tested: Cisco FTD/FMC Access Control Policy rule actions and Snort inspection
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/access_control_rules.html
Topics
Community Discussion
No community discussion yet for this question.
