IPS Block

Options
jef
jef Posts: 87  Ally Member
First Comment Second Anniversary
edited June 27 in USG FLEX H Series

When the "IPS" triggers a Block on a rules infraction, is there a place where these new rules, or a specific rule that its blocking, gets loaded or listed?

I looked in "Security Policy/ Policy Control". Nothing seems to be there.

As an example in the IPS logs I find:
"FTP login failed attempt Action:Reject Severity:high " note="ACCESS BLOCK" user="" devID="7049a200a98f" cat="IPS" action="ACCESS BLOCK""

Which is a legitimate "Block" on a IP4 address that is attempting to force FTP access.
So it is a good thing that IPS shut this IP4 address down..
But, where would I find the Rules for these automatically created "Blocks" and are they permanent?

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,529  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited July 2

    Hi @jef,

    IPS is a security service that requires a gold security pack license, GSP license, therefore, if the license is expired, this function will be disabled.

    Please help to navigate to Menu > Security services > IPS to find the current signature. Below is an example.

    image.png

    Please feel free to ask if you would like to know more.

    Zyxel Melen