Best practices for fastpath prefiltering
When you use the fastpath action in a prefilter rule, the matching traffic bypasses inspection and is simply transmitted through the device. Use this action for traffic that you can trust and that would not benefit from any of the security features available.
-
VPN traffic that is going through the device. That is, the device is not an endpoint in the VPN topology.
-
SQL traffic between trusted endpoints on the internal network.
-
Scanner traffic. Scanner probes can create a lot of false-positive responses from intrusion policies.
-
Voice/video.
-
Backups.
-
Management traffic (sftunnel) that traverses Firewall Threat Defense devices. Performing deep inspection on management traffic (using access control policies) can cause issues. You can prefilter based on port TCP/8305 between the management center and managed devices.