Hi,
we have an XG330 on 17.5.3. Had problems with packages being dropped due to an ips signature.
Configured an ips exception, as explain in KB132879. Somehow its not working tho...
This thread was automatically locked due to age.
Hi,
we have an XG330 on 17.5.3. Had problems with packages being dropped due to an ips signature.
Configured an ips exception, as explain in KB132879. Somehow its not working tho...
FW 17.5.3
Thanks for the tip, unfortunately its not working.. same drops..
Hi peerscholz
from my understanding of the IPS on the XG you have your IPS in reverse, it should be LAN to DMZ.
Ian
Does the name of the ips policy matter?
I thought what matters is that the ips policy say to allow the packages for configured ips id's..
EDIT: Additionally we have the same drops coming from WAN on a different ips policy (right name), with the same ips exceptions on that ips policy
Hi,
We never recommended a default IPS policy on any brand of firewall. The IPS is a very critical part of the firewall. It may impact on Firewall resources like CPU, RAM and increase the delay in packets delivery etc.
I have a habit to always configure a customized policy for IPS so I can do a finetune the IP. A predefined policy is ideal for all type of environment as you have mix OS, systems etc.
Hi,
We never recommended a default IPS policy on any brand of firewall. The IPS is a very critical part of the firewall. It may impact on Firewall resources like CPU, RAM and increase the delay in packets delivery etc.
I have a habit to always configure a customized policy for IPS so I can do a finetune the IP. A predefined policy is ideal for all type of environment as you have mix OS, systems etc.