IPS Block




When the "IPS" triggers a Block on a rules infraction, is there a place where these new rules, or a specific rule that its blocking, gets loaded or listed?
I looked in "Security Policy/ Policy Control". Nothing seems to be there.
As an example in the IPS logs I find:
"FTP login failed attempt Action:Reject Severity:high " note="ACCESS BLOCK" user="" devID="7049a200a98f" cat="IPS" action="ACCESS BLOCK""
Which is a legitimate "Block" on a IP4 address that is attempting to force FTP access.
So it is a good thing that IPS shut this IP4 address down..
But, where would I find the Rules for these automatically created "Blocks" and are they permanent?
All Replies
-
Hi @jef,
IPS is a security service that requires a gold security pack license, GSP license, therefore, if the license is expired, this function will be disabled.
Please help to navigate to Menu > Security services > IPS to find the current signature. Below is an example.
Please feel free to ask if you would like to know more.
Zyxel Melen0
Categories
- All Categories
- 435 Beta Program
- 2.7K Nebula
- 176 Nebula Ideas
- 118 Nebula Status and Incidents
- 6.1K Security
- 428 USG FLEX H Series
- 298 Security Ideas
- 1.6K Switch
- 79 Switch Ideas
- 1.2K Wireless
- 44 Wireless Ideas
- 6.7K Consumer Product
- 274 Service & License
- 422 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 89 Security Highlight