Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Basilio_Alcant1
Contributor

IPS Protection

I set the below protection to "Prevent" override but the IPS Profile action (detect) is still taking precedence, in other words it seems like the override option is not working as expected any ideas?

Protection

Apache logging package Log4j 2 versions 2.14.1 and below (CVE-2021-44228

0 Kudos
3 Replies
Timothy_Hall
Legend Legend
Legend

Did you reinstall the Threat Prevention policy?  Not just Access Control...

Also make sure you do not have some kind of broad-ranging exception switching the action to Detect.

Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones
0 Kudos
Dario1
Participant

Just to clarify are we saying? If the FW cluster IPS Activation Mode  is set to Detect only (NOT according to TP policy) and we change the Log4J protection override to "Prevent" this will drop Log4j despite the gateway cluster being in Detect? Many Thanks

0 Kudos
Timothy_Hall
Legend Legend
Legend

See my response here, what you want is possible but not easy:

Set Activation as Staging Mode

Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events