300-710 · Question #316
A company is deploying Cisco Secure Firewall Threat Defense with IPS. What must be implemented in inline mode to pass the traffic without inspection during spikes and ensure that network traffic is…
The correct answer is D. Set the Snort Failsafe option. To ensure continuous network traffic flow during IPS inspection spikes or failures in inline mode, the Snort Failsafe option must be enabled on Cisco Secure Firewall Threat Defense.
Question
A company is deploying Cisco Secure Firewall Threat Defense with IPS. What must be implemented in inline mode to pass the traffic without inspection during spikes and ensure that network traffic is kept?
Options
- AChange the interface mode to Routed
- BSelect Propagate Link State
- CIncrease the MTU to 9000
- DSet the Snort Failsafe option
How the community answered
(57 responses)- A9% (5)
- B2% (1)
- C4% (2)
- D86% (49)
Why each option
To ensure continuous network traffic flow during IPS inspection spikes or failures in inline mode, the Snort Failsafe option must be enabled on Cisco Secure Firewall Threat Defense.
Changing the interface mode to Routed alters the fundamental network deployment from Layer 2 inline inspection to Layer 3 routing, which does not address IPS bypass during spikes.
Propagate Link State is a feature used in high availability or specific network designs to synchronize interface link status and does not provide an IPS bypass mechanism for overload.
Increasing the MTU to 9000 (Jumbo Frames) can improve network performance for large packets but does not provide a mechanism to bypass IPS inspection during high load or failure conditions.
The Snort Failsafe option (also known as Bypass or Fail-Open) is specifically designed for inline IPS deployments to ensure that if the Snort inspection engine becomes overloaded or crashes, traffic will bypass inspection and continue to flow through the device, preventing network disruption.
Concept tested: Cisco FTD IPS Snort failsafe
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/621/configuration/guide/fpmc-config-guide-v621/intrusion_policies_and_rules.html#_Filter_Action_Default_Action_Default_Values_for_Intrusion_Policies
Topics
Community Discussion
No community discussion yet for this question.