Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cem82
Contributor
Jump to solution

IPS detect logs only after enabling anti bot blade

Hi
Initially we only had IPS blade enabled and were not getting logs for hosts under the global exceptions which we expected. Only after enabling anti bot blade we are now seeing IPS logs for hosts covered by global exception. I have checked several of the signatures under the IPS profile and they are set to prevent, however these are detect logs. We are still seeing prevent IPS logs for hosts that are not in the global exception

Has anyone come across this or what am I overlooking?  We are running R81.10 mgmt and GW JHF 66 on both

IPS profile
Only has IPS blade ticked

AntiBot profile
Only has Antibot blade ticked
Set to detect only under GW properties

Global exception
Protected Scope = Any
Source = Specific network groups
Protection/Site/File/Blade = IPS
Action = Inactive

 

Threat Prevention custom policy
"Threat Prevention" layer name
Scope any <IPS profile name>

Track = log

"Anti Bot" layer name
Scope one specific network <AntiBot profile name>

Track = log

0 Kudos
1 Solution

Accepted Solutions
yalmog
Employee
Employee

Hi
R81.10 JHF 79 contain a fix (PMTR-77524) that Global-Detect's action wrongly take precedence over Exception's action.

View solution in original post

6 Replies
PhoneBoy
Admin
Admin

Just to clarify your situation:

  • You have a separate Threat Prevention rules for IPS and Threat Prevention using profiles
  • You have global exceptions that relate to IPS

What are the precise logs you're seeing?
Please provide a screenshot or two of the log cards in question (sensitive details redacted).

 

0 Kudos
cem82
Contributor

The same IPS profile and exception is on another GW, only difference is that it doesn't have AB profile/rules and not seeing these detect logs, only the IPS where the source isn't part of the exclusion group.

 

This is log for where source is part of the exclusion group " "Blade:IPS" "action:Inactive"

IPS Detect log.JPG

Prevent log for a source that is not in the exclusion group

IPS Prevent log.JPG

TP policy'.JPG

Antibot layer.JPG

 

Global exception.JPG

0 Kudos
PhoneBoy
Admin
Admin

Ok, so you're using multiple threat layers too.
I think your best bet in this situation is a TAC case.

0 Kudos
cem82
Contributor

Cool thanks, suspected that'd be the case. 

0 Kudos
the_rock
Legend
Legend

I had similar case with client couple of years back and TAC had them make some changes in threat prevention profile to make this work. IM really sorry, but I cant recall what was done. Once you find a solution, please share it here.

0 Kudos
yalmog
Employee
Employee

Hi
R81.10 JHF 79 contain a fix (PMTR-77524) that Global-Detect's action wrongly take precedence over Exception's action.