This content has been marked as final. Show 1 reply
Firewall Adaptive or Learn mode is an "aid" to firewall rule tuning. In some cases, adaptive mode may not correctly learn the traffic.
There's been some changes around this area in HIP 7.0 patch 4 which was just released 3/11/09 and is now available on the McAfee download site with your valid grant#.
I would suggest retesting this with patch 4 applied. If there is still a problem, obtain 2 network traces (1 with fw off & 1 with fw on). Compare the 2 sniffs to determine the what traffic is missing. Manually add a rule for the traffic to your policy and retest.
If you determine there is a bug or you still have an issue, open a ticket with McAfee support.