04-04-2016 01:16 PM - edited 03-10-2019 06:35 AM
Hi Comunity,
I wanted to ask about an alert fired on the IPS. The signature has a high severity, but no actions were taken by the IPS. I checked the Event Action Filters and there is not any filter to avoid apply actions to this traffic.
The alarm was:
Thanks.
04-06-2016 12:22 PM
Is your IPS policy set to block or monitor only?
Thank you for rating helpful posts!
04-07-2016 12:45 PM
Hi,
By default, the signature has a High severity and the default action is "Produce Alert". Otherway, with a Hihgh Risk Rating, the Event Action Overrides has the acction "Deny Packet Inline" to add.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide