Announcement

Collapse
No announcement yet.

IPS - Disabled rules still blocking

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • IPS - Disabled rules still blocking

    Hi, I'm having issues with IPS rules. After some reading, I'm pretty sure I understand how things are supposed to work.
    I was seeing a lot of unnecessary blocking from Classtype=Protocol-command-decode.
    So I disabled that classtype altogether. However, I am still seeing it showing in by blocked events.
    I have tried more specific rules as well, such as blocking that classtype with specific messages and still no luck.
    Please let me know if there is somewhere that I can find more information on this if I am doing something incorrectly.
    Thanks.

    Click image for larger version

Name:	rules.JPG
Views:	1
Size:	89.9 KB
ID:	387182
    Click image for larger version

Name:	blockedevents.JPG
Views:	1
Size:	97.9 KB
ID:	387183

  • #2
    This seems pretty similar to what others were complaining of a couple years back. No solutions suggested for their issue either.
    forums.untangle.com/intrusion-prevention/41602-message-rule-not-applied-properly.html

    Comment


    • #3
      First rule match wins...

      Putting the pass below the block... never works. Move that rule up in the list.
      Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
      NexgenAppliances.com
      Phone: 866-794-8879 x201
      Email: [email protected]

      Comment


      • #4
        Thanks for the tip, I didnt realize that the list was also the processing order. That makes sense.

        Comment

        Working...
        X
        😀
        🥰
        🤢
        😎
        😡
        👍
        👎