Tuesday, April 16, 2019

Cisco Firepower message: SFR requested ASA to bypass further packet redirection and process TCP flow from Interface name/IP:port to Interface name IP:port locally

From what I've read this means the Firepower module is saying it's seen enough of this particular traffic flow to determine that it doesn't need to inspect it any longer, and please don't send me any more of it.

The message continues to appear for the same traffic flow and is repeated quite often, sometimes a few times a second, so I was wondering if the ASA is ignoring it or if that's normal. I did a fair bit of searching but didn't come up with anything definitive.

Edit: Sorry about the extra long title, thought it would wrap.



No comments:

Post a Comment