Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
G-
Participant
Jump to solution

r81.20 How to create an IPS exception using the 'proxied source ip' field?

We have a WAF (Web Application Firewall) acting as external protection for our internally hosted web servers.

We also have a vulnerability scanner external to our network probing for issues which are generating a large number of IPS alerts.

When I look at the logs, the source IP field is the WAF internal address, and the 'Proxied Source IP' field contains the source IP of the external scanner.

I need to be able to create an exception for these IPS alerts, but there doesn't seem to be a way to specify the proxied source IP field in the exception, you can only seem to use the internal address of the WAF. I can't use this as it would blind us to probes from other external IP's that were getting through the WAF for some reason.

Is there a way to achieve the IPS exception for a specific proxied source IP?

Thx.

0 Kudos
1 Solution

Accepted Solutions
Wolfgang
Authority
Authority

@G- that's not possible. There was a similar post IPS exception based on Proxied Source IP? - Check Point CheckMates

maybe @Timothy_Hall idea could work. 

View solution in original post

0 Kudos
4 Replies
Wolfgang
Authority
Authority

@G- that's not possible. There was a similar post IPS exception based on Proxied Source IP? - Check Point CheckMates

maybe @Timothy_Hall idea could work. 

0 Kudos
G-
Participant

Thanks for the response. I tried searching but obviously missed that one. I'll have a look at the idea proposed. Cheers.

Timothy_Hall
Legend Legend
Legend

You also might be able to create a custom Snort IPS rule matching the proxy HTTP header field, import it, then create an exception matching that custom Snort rule with an action of Inactive.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
G-
Participant

Thanks for the additional idea Timothy. To be honest, I doubt I have enough time to learn how to do all that, I'm going to lean on the WAF supplier to create a unique SNAT for the external scanner and 'cheat' 🙂

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events