IPS Block

Options
jef
jef Posts: 84  Ally Member
First Comment Second Anniversary
edited June 27 in USG FLEX H Series

When the "IPS" triggers a Block on a rules infraction, is there a place where these new rules, or a specific rule that its blocking, gets loaded or listed?

I looked in "Security Policy/ Policy Control". Nothing seems to be there.

As an example in the IPS logs I find:
"FTP login failed attempt Action:Reject Severity:high " note="ACCESS BLOCK" user="" devID="7049a200a98f" cat="IPS" action="ACCESS BLOCK""

Which is a legitimate "Block" on a IP4 address that is attempting to force FTP access.
So it is a good thing that IPS shut this IP4 address down..
But, where would I find the Rules for these automatically created "Blocks" and are they permanent?