Dear All,
There is an action in the IPS policy "Bypass Session" and as per documents "Bypass Session - Allows the entire session if detects any traffic that matches the signature." and recommendation for the same is:
"To save resources and avoid latency, set action as “Bypass Session” as in this, if the initial packets match the signature then the rest of the session packets will not be scanned at all."
Is he talking about the signatures which are having the default action "Allow" or for all signatures? Why I am asking this question because suppose there is a signature with Critical and default action for this packet is dropped, at this condition what will happen if I will select an action as "Bypass Session"?
Regards,
Deepak Kumar
This thread was automatically locked due to age.