IPS Block
Ally Member
When the "IPS" triggers a Block on a rules infraction, is there a place where these new rules, or a specific rule that its blocking, gets loaded or listed?
I looked in "Security Policy/ Policy Control". Nothing seems to be there.
As an example in the IPS logs I find:
"FTP login failed attempt Action:Reject Severity:high " note="ACCESS BLOCK" user="" devID="7049a200a98f" cat="IPS" action="ACCESS BLOCK""
Which is a legitimate "Block" on a IP4 address that is attempting to force FTP access.
So it is a good thing that IPS shut this IP4 address down..
But, where would I find the Rules for these automatically created "Blocks" and are they permanent?
All Replies
-
Hi @jef,
IPS is a security service that requires a gold security pack license, GSP license, therefore, if the license is expired, this function will be disabled.
Please help to navigate to Menu > Security services > IPS to find the current signature. Below is an example.
Please feel free to ask if you would like to know more.
Zyxel Melen0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.3K Security
- 515 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight
Zyxel Employee
