09-13-2022 09:37 PM
I have created security intelligence block list but sometimes it allows the connections like the one highlighted and it is identified as attackers.
Is that because the intrusion policy is set to detection not prevention?
Solved! Go to Solution.
09-15-2022 12:50 AM - edited 09-15-2022 12:56 AM
Are you talking about the "Drop when inline" setting?
What is the mode of the device and type of interfaces?
This is the setting I mentioned:
09-14-2022 05:40 AM - edited 09-14-2022 05:41 AM
The Reason column seems to indicate that you have set the action to "Monitor-only" and not "Block" for that Security Intelligence category. If so, my understanding is that the result is that no requests are blocked, not even the lower four in your screenshot.
09-14-2022 08:54 PM
The Monitor-Only on the intrusion policy not the security intelligence. will that affect it?
09-15-2022 12:50 AM - edited 09-15-2022 12:56 AM
Are you talking about the "Drop when inline" setting?
What is the mode of the device and type of interfaces?
This is the setting I mentioned:
09-15-2022 01:05 AM
you are correct, I missed this settings. thank you!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide