The Scanning exceptions feature bypasses the scanning of traffic from a configured VLAN, TCP, or UDP port. The scanning exceptions configurations that are defined can be enabled or disabled at the Sensor level.
Note
Scanning exception feature rules are applied to both the Sensors in a fail-over pair. On creating a fail-over pair, the template Sensor rules are copied to the peer Sensor.
Prior to 6.1, this feature was supported using the following Sensor CLI commands:
- layer2 forward tcp <enable | disable><0-65535>[<0-65535>]
- layer2 forward udp <enable | disable><0-65535>[<0-65535>]
- layer2 forward vlan <enable|disable> <0-4095> [<0-4095>]
- layer2 forward vlan <enable|disable> <0-4095>[<0-4095>] <interface <all|interfaceA-interfaceB>>
- layer2 forward clear
Scanning Exceptions feature is supported only in the following Sensor models:
- M-8000
- M-6050
- M-4050
- M-3050
- M-2950
- M-2850
- NS9300
- NS9200
- NS9100
- NS7350
- NS7250
- NS7150
- NS7300
- NS7200
- NS7100
- NS5200
- NS5100
- NS3200
- NS3100
Following models does not support the Scanning Exception feature:
- M-1450
- M-1250
- NS3500
Note
Scanning exceptions rules can be configured on ports running in inline mode. Once set, these rules take precedence over Firewall access rules. Fail-over ports and M-8000 interconnect ports cannot be configured for scanning exceptions