Results 1 to 3 of 3
  1. #1
    Newbie
    Join Date
    Jan 2017
    Posts
    3

    Default IPS logs fine but never blocks even though the rules list has block enabled

    Background:

    * IPS enabled and restarted the host box. Also done several IPS app restarts.
    * Run the IPS setup wizard. Results in 22,330 log rules enabled
    * For attempted-recon classtype I manually checked block for 27 rules
    * When I go to Reports > All Events log I see a good log and status page has 1000's of sessions scanned and 0 blocked
    * Rules that are blocked in the rules list never show as blocked in the report (false). I am using a rule (SID:7, GID:122, CID:4) that is getting hit every couple of minutes so I am expecting it to be blocked, but never does.

    Any ideas?

    Thanks,
    SparcEE
    Last edited by SparcEE; 04-14-2017 at 09:36 PM. Reason: typo

  2. #2
    Untangler
    Join Date
    Jul 2009
    Posts
    62

    Default

    I am seeing the same thing.... Intrusion Prevention detected 7900 attacks.... with nothing blocked on the graph... just detections. Not sure if is blocking the report graph is broke or if it is only logging and not blocking... Suggestions?

    ... I see from searching the forum and IPS doesn't block anything by default... you have to turn it on manually as some blocks might block legit traffic.
    Last edited by automationstation; 04-23-2017 at 08:40 AM. Reason: Found Solution

  3. #3
    Untangler jcoffin's Avatar
    Join Date
    Aug 2008
    Location
    Sunnyvale, CA
    Posts
    5,928

    Default

    Quote Originally Posted by SparcEE View Post
    * Rules that are blocked in the rules list never show as blocked in the report (false). I am using a rule (SID:7, GID:122, CID:4) that is getting hit every couple of minutes so I am expecting it to be blocked, but never does.
    Are those rules marked as logged? It does work correctly. I would post a snapshot of the blocked rule and the events with the same SID.

    12.2-ips-block-event.jpg
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2