IPS Block
Ally Member
When the "IPS" triggers a Block on a rules infraction, is there a place where these new rules, or a specific rule that its blocking, gets loaded or listed?
I looked in "Security Policy/ Policy Control". Nothing seems to be there.
As an example in the IPS logs I find:
"FTP login failed attempt Action:Reject Severity:high " note="ACCESS BLOCK" user="" devID="7049a200a98f" cat="IPS" action="ACCESS BLOCK""
Which is a legitimate "Block" on a IP4 address that is attempting to force FTP access.
So it is a good thing that IPS shut this IP4 address down..
But, where would I find the Rules for these automatically created "Blocks" and are they permanent?
All Replies
-
Hi @jef,
IPS is a security service that requires a gold security pack license, GSP license, therefore, if the license is expired, this function will be disabled.
Please help to navigate to Menu > Security services > IPS to find the current signature. Below is an example.
Please feel free to ask if you would like to know more.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 727 USG FLEX H Series
- 372 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 57 Wireless Ideas
- 7.1K Consumer Product
- 318 Service & License
- 511 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Zyxel Employee
