Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Piet_vd_Maas
Contributor

HCP - Threat Prevention Protections impact

Hi All,

When I'm looking to my HCP report under Threat Prevention > Protections > Protections Impact I see a lot of 'Applictions' instead of IPS.

The applications that are in the report aren't configured in any rule. Is there a way to finetune this?

 

SmartConsole Extensions Threat Prevention 

CCSE - CCVS
0 Kudos
5 Replies
Tal_Paz-Fridman
Employee
Employee

Adding @Andy_Yelnik 

0 Kudos
Timothy_Hall
Champion
Champion

If you have an APCL/URLF rule with Service & Application set to "Any" also with Detailed Logging set (such as the cleanup rule), overhead will be expended identifying & logging these applications which is what you are seeing in hcp.  You can set Track for these rules to just "Log" but the specific applications matching this rule will no longer be detected and logged.

Updated 2023 IPS/AV/ABOT R81.20 Course now
available at maxpowerfirewalls.com
0 Kudos
Piet_vd_Maas
Contributor

Hi Timothy,

The only rules that these applications can hit are the 'Cleanup Rules' with action Drop and track Log.

We've 1 other rule to block traffic to internet with action Reject but only track Log

CCSE - CCVS
0 Kudos
Piet_vd_Maas
Contributor

Is there a way to find the rule(s) that is/are responsible for this traffic?

CCSE - CCVS
0 Kudos
the_rock
Legend
Legend

I also saw that in web version of HCP for R81.20, but did not pay much attention to it.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events