ā06-27-2016 08:46 AM - edited ā03-10-2019 06:38 AM
i am seeing a strange issue with my firesight URL filtering setup
am seeing an intrusion block for website that is matching an allow rule
also the intrusion policy rule that is being matched is disabled.
how is that possible ?
ā06-27-2016 09:51 AM
Tejas,
Could you add more information about the problem? Please add some screenshots from the connection events, and screenshot of your Access control Policy in order to understand the issue and the way the traffic is being analyzed by the Firewall Engine.
ā06-27-2016 10:01 AM
ā06-27-2016 12:23 PM
Tejas,
The problem is not the object you created to allow the URL. Basically, your last line of defense (Intrusion Policy) has detected some anomalous content in that specific connection and now you have to confirm if it is a false positive or not.
In order to identify the rule this connection hits, go to the intrusion events and filter it by initiator IP and then download the capture for that event.
To confirm if it is a FP or FN, please open a case with TAC by referencing the GID you are matching, and submitting the capture retrieved previously.
ā06-28-2016 10:21 PM
Hello Tejas,
Have you verified if this blocked Intrusion rule is called in the Advanced option of Access control policy rule ?
Policies > Access Control > Click on Edit button > Advanced
Verify if the Intrusion policy is not called here.
Regards
Jetsy
ā06-29-2016 05:00 AM
the problem is the rule being referenced is actually disabled in the intrusion policy.
it is not set to drop.
thats why is surprising that i am seeing an intrusion block
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide