4 Attachment(s)
Rules not evaluating properly after latest 3-19-20 release
When I set threat prevention rules they seem to be applying as "OR" statements, instead of "AND". I created this rule:
Attachment 9981
This is my All Web Events report after enabling that rule:
Attachment 9982
As you can see it allowed a High Risk IP through with port 80 being the only matching part.
This is my Blocked Web Events while the rule is active:
Attachment 9983.
And this is what it looks like with the rule off:
Attachment 9984
The only successful workaround I've been able to come up with is only adding the Source IP Address to a Pass rule in threat prevention. I would like these rules to apply as they should as I don't want to open every port for each IP Address "pass". Just the port I want them to access. Anything else you need from me please let me know.