Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Basilio_Alcant1
Contributor

IPS Protection

I set the below protection to "Prevent" override but the IPS Profile action (detect) is still taking precedence, in other words it seems like the override option is not working as expected any ideas?

Protection

Apache logging package Log4j 2 versions 2.14.1 and below (CVE-2021-44228

0 Kudos
3 Replies
Timothy_Hall
Legend Legend
Legend

Did you reinstall the Threat Prevention policy?  Not just Access Control...

Also make sure you do not have some kind of broad-ranging exception switching the action to Detect.

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
0 Kudos
Dario1
Participant

Just to clarify are we saying? If the FW cluster IPS Activation Mode  is set to Detect only (NOT according to TP policy) and we change the Log4J protection override to "Prevent" this will drop Log4j despite the gateway cluster being in Detect? Many Thanks

0 Kudos
Timothy_Hall
Legend Legend
Legend

See my response here, what you want is possible but not easy:

Set Activation as Staging Mode

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events