Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dehaasm
Collaborator

IPS exclusions still show alert in logs

We have configured an exclusion for specific attack signature FTP Bounce and we see that this is not blocked anymore but is logged as Detect, however we also see log type Alerts and sometimes log type Log with IPS action Detect (this is expected).

 

The custom threat prevention policy is not configured with track Alert only Log and Forensic.

How can we suppress the Alerts generated somehow by IPS blade?

 

Is the only solution perhaps to completely bypass this with a seperate IPS profile with IPS blade disabled?

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

Can you show log cards of the relevant logs (sensitive details redacted)?
Please also provide version/JHF level of gateways/management.

0 Kudos
dehaasm
Collaborator

This is the unexpected alert log besides of this 50% of the time we also see normal IPS Detect log version is R81.10 take 81

0 Kudos
PhoneBoy
Admin
Admin

I suspect the reason this isn't working in the Threat Protection profile is because this particular protection is actually enforced in the Firewall (i.e. it's a Core Protection).
Did you disable Alert logging in the protection itself?
Also, changes to this protection require pushing the Access Policy as this protection is enforced in the Firewall. 

image.png

0 Kudos
Timothy_Hall
Legend Legend
Legend

Core Activations/Protections are much different than IPS ThreatCloud signatures and have their own set of profiles and exceptions separate from the rest of Threat Prevention, which causes a lot of confusion.  This particular FTP Bounce protection and three others are very bad offenders for intensifying this confusion as described in my IPS/AV/ABOT Immersion course:

 

coreact.png

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events