Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Basilio_Alcant1
Contributor

IPS Protection

I set the below protection to "Prevent" override but the IPS Profile action (detect) is still taking precedence, in other words it seems like the override option is not working as expected any ideas?

Protection

Apache logging package Log4j 2 versions 2.14.1 and below (CVE-2021-44228

0 Kudos
3 Replies
Timothy_Hall
Champion
Champion

Did you reinstall the Threat Prevention policy?  Not just Access Control...

Also make sure you do not have some kind of broad-ranging exception switching the action to Detect.

New 2021 IPS/AV/ABOT Immersion Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos
Dario1
Explorer

Just to clarify are we saying? If the FW cluster IPS Activation Mode  is set to Detect only (NOT according to TP policy) and we change the Log4J protection override to "Prevent" this will drop Log4j despite the gateway cluster being in Detect? Many Thanks

0 Kudos
Timothy_Hall
Champion
Champion

See my response here, what you want is possible but not easy:

Set Activation as Staging Mode

New 2021 IPS/AV/ABOT Immersion Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos