SNCF Knowledge Category

FTD Prefilter Policy

October 4th, 2022

FTD Prefilter Policy: the first level of access control and gives the capability to allow or filter a specific traffic at L3/L4 without the need to be forwarded to CPU intensive access control policy. It is also known as “fastpath” because it quickly allows or denies traffic, without deep packet inspection.

For example, you might want to allow ICMP for troubleshooting purposes and also drop Telnet traffic for security reasons. They do not need to be inspected by CPU-intensive engines like access-control policy, IPS policy, file policy and so on.

The Prefilter Policy is handled in the LINA engine, whereas the Access Control Policy is handled in SNORT. The main difference of the two policies is the inspection depth.

Snort_engine_vs_Lina_engine.jpgaaa