- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- CloudGuard - WAF
- :
- Re: How to create an exception rule for a specific...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to create an exception rule for a specific attack in a given uri path?
If a false positive is noticed on a certain path, how can I set up a rule to accept that characteristic of the request path? Is there a manually way to fine tune or accept certain IPS or WAF signatures for a specific endpoint? I have already tried some options here in the Rules/Exceptions without success.
Thank you in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had customer ask me the same question recently and TAC provided the same as @Bryan-Smith
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the reply, Mr. Bryan-Smith.
Yes, I understand that section shows us how to create an exception for a query string parameter, but I supose this would completely bypass the URI path checking. So, I don't see how to specifically bypass something related to a false positive one other than disable all checking in there.
So, that's my million dollar question, how to bypass not all, but single signature?
By wildcard matching the signature content in the uri one by one? Maybe?
Bests regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I am understanding the request correctly, you would need to include the IPS "Protection Name" that you are looking to bypass. The list of them can be found in the release notes. By combining multiple factors your exception can be very specific in nature and not bypass everything.
https://portal.checkpoint.com/dashboard/appsec/cloudguardwaf#/waf-policy/release-notes/ips-signature...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, man, for the info!
I appreciate it.
Best regards.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No problem!
