Skip to main content
buddyd
New Member
June 12, 2014
Question

dropped vs detected

  • June 12, 2014
  • 3 replies
  • 21467 views
Hi Folks, We have a pair of FG 240D' s sitting behind our ASA. These were config' d by a vendor so they are a black box to us, looking for what should be to the forum some simple answers. The vendor setup an outside VDOM with DoS policies. For most attacks, we are seeing a status of dropped which I' m told means blocked. For anomalies, we get a status of detected, which is making management question the configuration. What is the difference between dropped and detected? Is " detected" a problem that is not dealt with? Many thanks in advance. buddyd

    3 replies

    Baptiste
    New Member
    June 12, 2014
    Hi, I guess : Dropped : paquets are dropped Detected : no action, just log
    buddyd
    buddydAuthor
    New Member
    June 12, 2014
    Thanks for the quick reply, Baptiste! Yeah, got a response from the vendor (finally) and he agreed the profile(s) should be modified to block, which has been done.
    Dipen
    New Member
    June 21, 2014
    Hi Initially go for the signature defaults, let it run for a couple of months then customize. This is to minimize false positives. Regards