- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IPS Analyzer Results
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Analyzer Results
I have read the other posts on the IPS Analyzer out there and realize that the protections listed as Threat Prevention protection # are coming from other blades. Is there a way to identify what blades these are coming from in the raw files that you run IPS Analyzer on? What is the best way to identify and remediate these?
Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Specific examples might help.
In general, App Control is the second most likely culprit as it also uses signatures and is in wide use.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is what my report looks like. The only blades currently enabled on this Cluster are Firewall, IPS, Anti-Bot, and Anti-Virus.
| Threat Prevention protection 21 |
|
| ROBOT TLS_RSA Scanning Attempt |
|
| Threat Prevention protection 1566 |
|
| Threat Prevention protection 190 |
|
| Threat Prevention protection 3 |
|
| Threat Prevention protection 2 |
|
| Threat Prevention protection 1582 |
|
| Threat Prevention protection 1583 |
|
| Threat Prevention protection 1584 |
|
| Threat Prevention protection 1585 |
|
| Threat Prevention protection 1586 |
|
| Threat Prevention protection 1587 |
|
| Threat Prevention protection 1581 |
|
| Threat Prevention protection 1568 |
|
| Threat Prevention protection 1567 |
|
| Threat Prevention protection 1597 |
|
| Threat Prevention protection 135 |
|
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Guessing these are Anti-Bot related but it's only a guess.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have these showing up as Critical Protections. What is the best way to find what these are apart from emailing Omer Shliva?
Threat Prevention protection 421
Threat Prevention protection 362
Threat Prevention protection 398
Threat Prevention protection 433
Threat Prevention protection 913
Threat Prevention protection 902
Threat Prevention protection 903
Threat Prevention protection 881
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
