Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MattDunn
Advisor

IPS Prevent Email Alerts

Jump to solution

Does anyone know if it's possible to set mail alerts on IPS Prevents?

I know you can set alerts in the Track dropdown on individual protections...

But what I need to to set mail alerts on any and all Prevents that happen from or to certain IP addresses.  We don't know ahead of time which protections will be triggered.  We just need to know straight away if a specific IP is involved in any "Prevent" action, without sitting in front of the logs hitting refresh 24x7.  Is this possible somehow?

Thanks 🙂

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

Assuming you are using gateways running at least R80.10, yes.  Set up a rule at the top of your TP  policy as shown below, with the offending IP address in the Protected Scope and the Track field including the Mail alert.  The built-in Strict profile prevents just about everything and would probably work well here, or you could clone the Strict policy and enable every possible signature in Prevent mode if you want, even signatures with Performance Impact rating of Critical which are only enabled manually by an Administrator.  Be sure to set up and test the mail alert as shown here: sk25941: Configuring 'Mail Alerts' using 'internal_sendmail' command

My IPS Immersion self-guided video series covers topics such as this in detail.

tp+alert.png

 

 

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

2 Replies
Timothy_Hall
Champion
Champion

Assuming you are using gateways running at least R80.10, yes.  Set up a rule at the top of your TP  policy as shown below, with the offending IP address in the Protected Scope and the Track field including the Mail alert.  The built-in Strict profile prevents just about everything and would probably work well here, or you could clone the Strict policy and enable every possible signature in Prevent mode if you want, even signatures with Performance Impact rating of Critical which are only enabled manually by an Administrator.  Be sure to set up and test the mail alert as shown here: sk25941: Configuring 'Mail Alerts' using 'internal_sendmail' command

My IPS Immersion self-guided video series covers topics such as this in detail.

tp+alert.png

 

 

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

MattDunn
Advisor

Thanks @Timothy_Hall .  You guided me to the missing thing....  I just didn't have the "Track" column showing!  Doh.  More caffeine needed 🙂

0 Kudos