Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Basilio_Alcant1
Contributor

IPS Protection

I set the below protection to "Prevent" override but the IPS Profile action (detect) is still taking precedence, in other words it seems like the override option is not working as expected any ideas?

Protection

Apache logging package Log4j 2 versions 2.14.1 and below (CVE-2021-44228

0 Kudos
3 Replies
Timothy_Hall
Legend Legend
Legend

Did you reinstall the Threat Prevention policy?  Not just Access Control...

Also make sure you do not have some kind of broad-ranging exception switching the action to Detect.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Dario1
Participant

Just to clarify are we saying? If the FW cluster IPS Activation Mode  is set to Detect only (NOT according to TP policy) and we change the Log4J protection override to "Prevent" this will drop Log4j despite the gateway cluster being in Detect? Many Thanks

0 Kudos
Timothy_Hall
Legend Legend
Legend

See my response here, what you want is possible but not easy:

Set Activation as Staging Mode

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events