04-04-2016 01:16 PM - edited 03-10-2019 06:35 AM
Hi Comunity,
I wanted to ask about an alert fired on the IPS. The signature has a high severity, but no actions were taken by the IPS. I checked the Event Action Filters and there is not any filter to avoid apply actions to this traffic.
The alarm was:
Thanks.
04-06-2016 12:22 PM
Is your IPS policy set to block or monitor only?
Thank you for rating helpful posts!
04-07-2016 12:45 PM
Hi,
By default, the signature has a High severity and the default action is "Produce Alert". Otherway, with a Hihgh Risk Rating, the Event Action Overrides has the acction "Deny Packet Inline" to add.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: