Firewall access rules are comparable to scanning exceptions in terms of functionality. Scanning exceptions also enable traffic to bypass the Sensor's inspection. However, firewall access rules provide more features for a more granular control.
If both scanning exceptions and Firewall access rules are configured, the Sensor processes scanning exceptions first. That is, only traffic that is allowed based on scanning exceptions are subjected to the Firewall access rules (stateless or stateful).
Scanning exceptions | Firewall access rules |
|---|---|
The Sensor processes these before the access rules. | The Sensor checks only those packets that did not match the scanning exception rules. If a packet had matched a scanning exception rule, it would have bypassed the Sensor. |
These rules allow the matched traffic to pass through the Sensor without inspection for attacks. There is no provision to drop the matched traffic. | The matched traffic can either be dropped or allowed to pass through. |
You cannot define the source or destination of the traffic in the rule. | You can apply the rule based on the source and destination of the traffic. You can set any of the following as the criteria for source and destination in case of advanced Firewall policies:
|
The criteria to match traffic can be TCP port numbers, UDP port numbers, or VLAN IDs. | Any default or custom Service rule objects except for custom Service rule object where the Protocol Number is 89. You can configure 89, but this traffic cannot be dropped as the Sensor ignores it by default. |
No option to specify direction or time. | You can apply the rule in the inbound, outbound, or both directions. In case of advanced Firewall policies, you can specify the time period when the Sensor must enforce a rule. |
You define the scanning exceptions at the Sensor level. The TCP- and UDP-based scanning exceptions are applied at the Sensor level. VLAN-based exceptions are applied at the Sensor or port-pair level. | Though Sensor (pre-device) level is what is recommended, you can apply these at the following levels:
|
Immediately after you define them, the Manager sends the scanning exceptions to the corresponding Sensor. Does not require a configuration update. | Needs a configuration update to take effect. |
Supported on NS-series Sensors | Supported on NS-series Sensors models except NS3500. |
Supported only in inline mode. | Supported in inline, SPAN, and tap mode. However, the response action in SPAN and tap mode do not affect the actual traffic. |
For more information on stateless access rules, see the topic Using stateless access rules.