Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Agust
Contributor

SAM rules and IPS

I would like if you could clarify an issue regarding the inspection performed by the IPS engine and the complementary operation with the SAM rules, because through logs we can see that the traffic that checks with some SAM rules then appears in a log as detect for the IPS rules, in which it should be prevent, according to the profile and rules applied.
Is this behavior correct if the SAM rule is applied first?
Thanks

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

What version/JHF?
What precise IPS protections are involved using what Threat Prevention profile and rules?

In any case, SAM rules should apply first.
Screenshots (with sensitive details redacted) will help.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events