Inspection interruption warnings during deployment

When you deploy configurations, the Inspect Interruption column in the deploy page indicates if a deployed configuration will restart the Snort process on the Firewall Threat Defense device. When the traffic inspection engine referred to as the Snort process restarts, inspection is interrupted until the process resumes. Whether traffic is interrupted or passes without inspection during the interruption depends on how the traffic is handled by the device. You can proceed with the deployment, cancel the deployment and modify the configuration, or delay the deployment until a time when deploying would have the least impact on your network.

During deployment, when the Inspect Interruption column indicates Yes and you expand the device configuration listing, an icon will highlight any configuration type that may restart the Snort process. Moving your pointer over the icon displays a message saying that deployment may interrupt traffic.

This table summarizes how the deploy page displays inspection interruption warnings.

Inspection interruption indicators

Type

Inspect interruption

Description

Firewall Threat Defense

Inspect Interruption (inspect interruption icon)Yes

At least one configuration would interrupt inspection on the device if deployed, and might interrupt traffic depending on how the device handles traffic. You can expand the device configuration listing for more information.

--

Deployed configurations will not interrupt traffic on the device.

Undetermined

The system cannot determine if a deployed configuration may interrupt traffic on the device.

Undetermined status is displayed before the first deployment after a software upgrade, or in some cases during a Support call.

Errors (error icon)

The system cannot determine the status due to an internal error.

Cancel the operation and click Deploy again to allow the system to redetermine the Inspect Interruption status. If the problem persists, contact Support.

sensor

--

The device identified as sensor is not the Firewall Threat Defense device; the system does not determine if a deployed configuration may interrupt traffic on this device.

For information on all configurations that restart the Snort process for all device types, see Configurations that restart the snort process when deployed or activated.