Hello Mates!!!
I'm trying to bypass an Anti-Bot IP Reputation Prevent on a specific IP address, but no exception I configure seems to take effect. Hoping someone has seen this behavior before.
Environment: R81.20
Problem
In SmartConsole logs I see Prevent entries from blade Anti-Bot, Protection Type IP Reputation, against destination 13.107.138.10 - a Microsoft IP belonging to subnet 13.107.136.0/22, which is part of the Office 365 Services Updatable Object (verified by checking the office365.C file on the gateway).
The matched rule is IPS.TO Internet (corresponding to Threat Prevention policy).

Since this IP is in a Microsoft-published range I want to also exclude it from Anti-Bot IP Reputation enforcement.
What I tried
I configured a Global Exception below:
- Protected Scope: Any
- Source: Any
- Destination: 13.107.138.10
- Protection/Site/File/Blade: Anti-Virus, IPS, Anti-Bot
- Action: Inactive
- Track: Log
The log still shows Prevent. The Matched Rules tab in the log details shows only the parent rule IPS.TO Internet - no reference to the exception.
I then tried this additional configuration, with the same result (no match): Action set to Detect instead of Inactive (based on the suggestion in this thread: IPS exception not working
The policy was properly installed via Install Policy -> Threat Prevention.
My Questions
- Is there something specific about how Anti-Bot IP Reputation handles exceptions that I'm missing? Does IP Reputation enforcement happen at a different level than the standard Threat Prevention policy evaluation, bypassing exceptions altogether?
- Has anyone successfully bypassed an Anti-Bot IP Reputation Prevent on a specific destination via Threat Prevention exceptions in R81.20? If so, what was the working configuration?
Any guidance is much appreciated. Screenshots attached.
Thank you