Inspection of packets that pass before traffic is identified

Inspection of packets that pass before traffic is identified is a network security process that

  • allows a few packets to pass initially for connection establishment and traffic identification,

  • enables features like URL filtering, application detection, rate limiting, and Intelligent Application Bypass to function properly, and

  • requires explicit configuration in access control policies to inspect, prevent, and generate events for these initial packets.

Configuration requirements

You must explicitly configure your access control policy to inspect these packets, prevent them from reaching their destination, and generate any events.

As soon as the system identifies the access control rule or default action that should handle the connection, the remaining packets in the connection are handled and inspected accordingly.