- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Threat Prevention - IPS policy
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Threat Prevention - IPS policy
Hi All
Can anyone clarify for me the below
1.Under the Threat Prevention, I see IPS and threat prevention layers, yet IPS is enabled on the Threat Prevention profile anyway.
Is the IPS layer just there for pre R80 or R77 software from when it was upgraded and is no longer needed?
2.Under the Threat prevention rule, if we click on the arrow, we get E-1.1 etc, are these just all the exceptions which also can be accessed under the Exceptions menu also?
cheers
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you don’t manage any pre-R80 gateways, you can remove the IPS layer.
The Threat Prevention exceptions may or not be listed as rules in the policy as the policy can be more granular.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you don’t manage any pre-R80 gateways, you can remove the IPS layer.
The Threat Prevention exceptions may or not be listed as rules in the policy as the policy can be more granular.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To further expand on what PhoneBoy said, here is the relevant page from my IPS/AV/ABOT video series that fully explains the Legacy IPS layer and how to get rid of it:
CET (Europe) Timezone Course Scheduled for July 1-2
