I'm getting IDS intrusion alerts from an IP that I put in firewall blocked list.
Is this a normal behavior?
I'm getting IDS intrusion alerts from an IP that I put in firewall blocked list.
Is this a normal behavior?
Hello!
By default any new created rules(Block IP List,...) are disabled for safety reasons. Enable firewall and this rule.
Firewall and block IP rule are both enabled.
I'm running Q2x v.5.2.48
I have probably over 100 blocked IPs in total including individual filters (blocked by SIP UA) and in manually maintained blocked IP group.
I'm getting IDS intrusion alerts from an IP that is in enabled firewall block rule.
Is this a normal behavior?
Last edited by afuchs; 11-17-2011 at 05:51 PM.
Hello!
Thank you for your good question.
The problem is that IDS chain is located higher than Blocked IP List in the IP Tables of Quadro.
So, the incoming packets(attacks) do not reach the Blocked IP List rule.
From user side this maybe not so expected behaviour, but this is the work of Quadro's IP Tables. Regardless of which rule blocks packets from unwanted sources you can be unworried about your Quadro security.
Regards,
Aram
Thanks for explaining IP table priorities.
It would be good if Alert check block table before it sends a false alarm.
There are currently 1 users browsing this thread. (0 members and 1 guests)