← CCNP Security: SCOR core and operations
03 / 8 · 50 MIN

Firewall, inspection, and layer-two protection

Relate policy actions to observation and actual enforcement.

Concept and mechanism

In Secure Firewall, different actions provide different guarantees. Trust permits a flow without the deep inspection expected from an Allow rule with an associated intrusion policy. Monitor can record a match while evaluation continues toward another action; an event is not automatic proof of blocking. Policy also follows an operational lifecycle: edit, save, deploy to the device, and verify results. Skipping this distinction creates reports where the editor shows configuration the target does not yet run. A passive sensor receives copies and can detect activity, but that point is not inline to directly drop original packets.

Guided application

In a fictional pilot, the team changes a partner exception to add inspection. Acceptance should confirm deployed state and rehearse authorized synthetic traffic and expected detection with rollback criteria. At layer two, DAI validates ingress ARP according to trust context and binding information. A static server may lack a DHCP binding; an appropriate ARP ACL first requires validation of the legitimate association. Indiscriminately marking every access port trusted resolves the symptom by removing checking from a wider surface. Retain ports, VLANs, associations, and rehearsal results in handover. The aim is to let RUN distinguish an application issue from a policy that works as configured but was designed around incorrect assumptions.

IN PRACTICE

Saving Allow with IPS does not prove the rule is already active on the firewall.

Common pitfalls

Event as blocking; Trust as inspected Allow; saved configuration as applied; broad exception for one static case.

Related topics: Risk, identity, and AI security · Encryption, VPNs, and APIs · Secure management and VPN diagnosis

Take this idea with you

Confirm intent, deployment, and effect separately.

Create account

Reference: Access control rules · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security