Hello community!
Looks like my IPS isn't work.
I have a cluster on border of my network with internet.
I enable https inspection and IPS blade, update IPS signatures database and try to test with checkme.
So, IPS information from security gateways:
[Expert@FW1_name:0]# ips stat
IPS Status: Enabled
Active Profiles:
Optimized
IPS Update Version: 635241547
Global Detect: Off
Bypass Under Load: Off
[Expert@FW2_name:0]# ips stat
IPS Status: Enabled
IPS Update Version: 635241547
Global Detect: Off
Bypass Under Load: Off
Honestly i don't know why FW2 have not Active Profiles but ok, i have two checkme tests and both tests was fully Vulnerable...
Regarding sk115236 i expect as minimum that Browser exploit section will be secure. Because my Active IPS profile include signature Cross-Site Scripting Scanning Attempt in "Prevent mode".
One more interesting thing that in sk115236 for Malware Infection test recommended enabling "D-Link 850L Router Remote Unauthenticated Information Disclosure" signature. But i didn't find this signature in list at all...
At the moment, I have familiarized myself with a huge number of problems related to IPS database updates, checkme checks, etc., but I have not been able to figure it out.
I'll add additional screenshots for help analyze situation.
Gaia version is R80.40 on management server and FWs