You can use stateless access rules to allow or block certain traffic without deeper inspection. These rules can prevent you from spending time or valuable Sensor resources on traffic that you completely trust or traffic that you want to completely avoid. You can use stateless access rules to bypass IPS inspection for trusted high-throughput applications like database backups. For asymmetric traffic, the traffic flowing in and out of the network may not be inspected by a Sensor. In such cases, you can configure the stateless access rules where each packet is inspected by the Sensor and not the complete traffic flow. The Sensor allows or blocks packets just based on L3 and L4 information in those packets.
Note
In stateless access rules, the Sensor inspects the traffic on per-packet basis. Post-inspection, the packets are either dropped or ignored depending on the response action configured. Due to per-packet inspection of the traffic flow, the stateless access rules results in noticeable drop in Sensor performance.
You can create stateless access rules in both advanced and classic Firewall policies. When compared to the regular access rules, the stateless access rules allow or drop traffic in a stateless manner. That is, for stateless rules the Sensor considers the traffic on a per-packet basis, whereas for service-based and application-based regular access rules it considers the entire flow. So, if you set the response as drop for stateless rules, the Sensor drops the packets, but for the regular rules, it drops the flow. You can use the stateless access rules during troubleshooting, where you might want the Sensor to drop packets of only one direction in a flow.
Notes:
When using stateless access rules, if IPv4 Address Range or IPv6 Address Range Rule Objects are used in the stateless or the stateful access rules, there can be a drop in the Sensor's performance. So, Trellix recommends that you avoid using these Rule Object types with stateless access rules.
The skipped SSL proxy counter increment with the stateless access/drop rules is only supported until version 11.1.5.122
You create a stateless access rule just like any other Firewall access rule but with the following differences:
Except for the response and application, all other columns are similar to the regular access rules in terms of functionality and usage.
In the response column of the rule, you select Stateless Ignore or Stateless Drop. The Sensor identifies a stateless access rule based on this selection only.
Stateless ignore – This is the same as ignore option. That is, the Sensor permits the packet without inspection for intrusions.
Stateless drop – The Sensor discards the packet.
In addition to inline mode, you can use the stateless access rules in SPAN and tap modes as well. However, in SPAN and tap, the stateless drop response action has no effect.
For the Application column, you can only select the following for stateless access rules:
You should leave it as Any.
You can select custom or default Service rule objects except for custom Service rule object with Port/Number set to 89. IP protocol number 89 relates to OSPF (RFC 1583), which is a routing protocol; this traffic bypasses the stateless access rules on the Sensor.
Custom Service Group rule object that uses Service rule objects except for ones where the Port/Number is 89.
The Sensor cannot log matched traffic to a syslog server. You cannot create a stateless access rule with logging enabled.
The stateless access rules generally target traffic that must be allowed or blocked on a priority basis (is allowed or blocked across your network). Also, the Sensor takes less time to process these rules. For these reasons, it is recommended that you define the stateless rules ahead of other similar regular rules and assign them at the pre-device level.