No announcement yet.

IPS - Disabled rules still blocking

This topic is closed.
  • Filter
  • Time
  • Show
Clear All
new posts

  • IPS - Disabled rules still blocking

    Hi, I'm having issues with IPS rules. After some reading, I'm pretty sure I understand how things are supposed to work.
    I was seeing a lot of unnecessary blocking from Classtype=Protocol-command-decode.
    So I disabled that classtype altogether. However, I am still seeing it showing in by blocked events.
    I have tried more specific rules as well, such as blocking that classtype with specific messages and still no luck.
    Please let me know if there is somewhere that I can find more information on this if I am doing something incorrectly.

    Click image for larger version

Name:	rules.JPG
Views:	1
Size:	89.9 KB
ID:	387182
    Click image for larger version

Name:	blockedevents.JPG
Views:	1
Size:	97.9 KB
ID:	387183

  • #2
    This seems pretty similar to what others were complaining of a couple years back. No solutions suggested for their issue either.


    • #3
      First rule match wins...

      Putting the pass below the block... never works. Move that rule up in the list.
      Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
      Phone: 866-794-8879 x201
      Email: [email protected]


      • #4
        Thanks for the tip, I didnt realize that the list was also the processing order. That makes sense.