Snort restart scenarios
A Snort restart scenario is a situation that
-
causes the traffic inspection engine, referred to as the
Snort process, on a managed device to restart, -
interrupts inspection until the process resumesWhether traffic drops during this interruption or passes without further inspection depends on how the assigned device handles traffic. Refer to Snort restart traffic behavior., and
-
may result in resource demands that cause a small number of packets to drop without inspection when you deploy.
Common snort restart triggers
Any of these scenarios cause the Snort process to restart:
-
You deploy a specific configuration that requires the Snort process to restart. For more information, refer to Configurations that restart the snort process when deployed or activated.
-
You make a change that immediately restarts the Snort process. For more information, refer to Actions that immediately restart the snort process.
-
Traffic activates the currently deployed Automatic Application Bypass (AAB) configuration. For more information, refer Configure automatic application bypass.
-
Enabling or disabling Logging connection events to RAM disk feature. For more information, refer the section Log to Ramdisk in Troubleshoot Drain of FMC Unprocessed Events.