Inspect traffic during policy apply
Inspect traffic during policy apply is an advanced access control policy general setting that enables managed devices to inspect traffic while configuration changes are applied, and allows inspection unless a deployed configuration requires the Snort process to restart.
Configuration options
You can configure this setting as follows:
-
Enabled — Traffic is inspected during the deployment unless certain configurations require the Snort process to restart. When a Snort restart is not needed, the system first uses the currently deployed access control policy to inspect traffic, then switches to the policy being deployed.
-
Disabled — Traffic is not inspected during the deployment. The Snort process always restarts when you deploy.
This graphic illustrates how Snort restarts can occur when you enable or disable Inspect traffic during policy apply.
Caution | When you deploy, resource demands may result in a small number of packets dropping without inspection. Additionally, deploying some configurations restarts the Snort process, which interrupts traffic inspection. Whether traffic drops during this interruption or passes without further inspection depends on how the target device handles traffic. Refer to Snort restart traffic behavior and Configurations that restart the snort process when deployed or activated. |