nerdexam
Cisco

300-710 · Question #316

A company is deploying Cisco Secure Firewall Threat Defense with IPS. What must be implemented in inline mode to pass the traffic without inspection during spikes and ensure that network traffic is…

The correct answer is D. Set the Snort Failsafe option. To ensure continuous network traffic flow during IPS inspection spikes or failures in inline mode, the Snort Failsafe option must be enabled on Cisco Secure Firewall Threat Defense.

Configuration

Question

A company is deploying Cisco Secure Firewall Threat Defense with IPS. What must be implemented in inline mode to pass the traffic without inspection during spikes and ensure that network traffic is kept?

Options

  • AChange the interface mode to Routed
  • BSelect Propagate Link State
  • CIncrease the MTU to 9000
  • DSet the Snort Failsafe option

How the community answered

(57 responses)
  • A
    9% (5)
  • B
    2% (1)
  • C
    4% (2)
  • D
    86% (49)

Why each option

To ensure continuous network traffic flow during IPS inspection spikes or failures in inline mode, the Snort Failsafe option must be enabled on Cisco Secure Firewall Threat Defense.

AChange the interface mode to Routed

Changing the interface mode to Routed alters the fundamental network deployment from Layer 2 inline inspection to Layer 3 routing, which does not address IPS bypass during spikes.

BSelect Propagate Link State

Propagate Link State is a feature used in high availability or specific network designs to synchronize interface link status and does not provide an IPS bypass mechanism for overload.

CIncrease the MTU to 9000

Increasing the MTU to 9000 (Jumbo Frames) can improve network performance for large packets but does not provide a mechanism to bypass IPS inspection during high load or failure conditions.

DSet the Snort Failsafe optionCorrect

The Snort Failsafe option (also known as Bypass or Fail-Open) is specifically designed for inline IPS deployments to ensure that if the Snort inspection engine becomes overloaded or crashes, traffic will bypass inspection and continue to flow through the device, preventing network disruption.

Concept tested: Cisco FTD IPS Snort failsafe

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/621/configuration/guide/fpmc-config-guide-v621/intrusion_policies_and_rules.html#_Filter_Action_Default_Action_Default_Values_for_Intrusion_Policies

Topics

#FTD IPS#Snort Failsafe#Inline mode#Traffic handling

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice