Good Morning
I was looking for some views around an exception on Threat Prevention if possible to see if there would be any security concerns, pros/cons etc that people could see.
No - 1
Name - Bypass IPSec and IKE
Protection Scope - * Any
Source - * Any
Destination - * Any
Protection/Site/File/Blade - N/A
Services - IKE_NAT_TRAVERSAL (Port udp/4500) / ESP (IP Protocol 50) / AH (IP Protocol 51) / IKE (Port 500) / SKIP (IP Protocol 57) / VPN1_IPSEC_encapsulation (Port 2746)
Action - All Blades are Disabled (Threat Emulation / Threat Extraction / IPS / Anti-Bot & Advanced DNS / Anti-Virus)
Track - None
No - 2
Name - Full Inspection
Protection Scope - * Any
Source - * Any
Destination - * Any
Protection/Site/File/Blade - N/A
Services - * Any
Action - All Blades are Enabled (Threat Emulation / Threat Extraction / IPS / Anti-Bot & Advanced DNS / Anti-Virus)
Track - Log/Packet Capture/Forensics
With the above rule No - 1, I am assuming this is going to bypass all Threat Prevention Protections on the setup for any site-to-site VPN's over these services/ports. As the "Protection Scope, Source, Destination" is set as * Any, this would include all VPN's within the company and any VPN including an external 3rd party.
I could maybe see a pro if the gateway has performance issues, you "might" want to exclude some of the above to assist with this. But then doing this, is it a con as you are not doing any Threat Prevention scanning on these services/ports.
Maybe this would be acceptable for company to company VPN's but any VPN including a 3rd party you would not want this bypass.
For rule No - 2 , I assume that once the site-to-site VPN is established, the 2nd rule would then scan the traffic inside the VPN with all the enabled blades.
If anyone has any advice on this, that would be much appreciated.
Thanks