Guest

Preview Tool

Cisco Bug: CSCvi65512 - FTD: AAB might force a snort restart with relatively low load on the system

Last Modified

Aug 10, 2018

Products (32)

  • Cisco ASA 5500-X Series Firewalls
  • Cisco FirePOWER Appliance 8120
  • Cisco Firepower Management Center 2500
  • Cisco FirePOWER Appliance 8360
  • Cisco FirePOWER Appliance 8260
  • Cisco FirePOWER Appliance 7050
  • Cisco FirePOWER Appliance 8140
  • Cisco AMP 7150
  • Cisco FirePOWER Appliance 8350
  • Cisco FirePOWER Appliance 8130
View all products in Bug Search Tool Login Required

Known Affected Releases

100.20(89)

Description (partial)

Symptom:
The inspection process in Firepower Threat Defense (Snort) might restart and dump a core file. Messages such as the following would be seen in /ngfw/var/log/messages:

detectionhealthd:detectionhealthd [WARN] AAB Invoked. Sending process snort SIGABRT to kill it and generate a core file

This might happen with no evidence of the snort processes being actually busy at the time.

Conditions:
Automatic application bypass (AAB) is enabled.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.