This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Guidelines for using Pre-defined IPS policies

I'm wondering how the modifiable IPS policies relate to the non-modifiable policies and what the recommendations are for using them. The first six seem clear enough (DMZ TO LAN, LAN TO WAN, etc.), assuming you have these standard zones set up, and I assume the policies have been written to perform security according to average traffic patterns between these zones.

However there is not much in the way of description or documentation for the other pre-defined policies: "generalpolicy", "lantowan strict policy", "lantowan general policy", and "dmzpolicy". What is the "general" policy? How do the "lantowan" policies compare to the basic "LAN to WAN" policy? And is the "dmzpolicy" like a "DMZ TO ANY" or something else? I'm assuming the lantowan "strict" simply looks for more signatures than the "general", but I'm wondering which of these is equivalent or closer to "LAN TO WAN" or what the other differences might be.

Also what is the recommendation for troubleshooting and tweaking IPS behavior with respect to false positives? I'm most concerned with LAN-WAN traffic, which is almost exclusively initiated by LAN users, and so I assume the various lan-to-wan policies are the appropriate policies to use. However they seem to overperform by causing legitimate traffic to prohibited and for users to receive HTTP errors. I notice this especially when communicating with servers in Amazon EC2. Is the solution to try using a modifiable lan-to-wan policy, monitor the IPS log for false positives, and then tweak the policy to disable those signature checks? Do the logs report sufficiently verbose information to do this kind of tuning?



This thread was automatically locked due to age.
Parents
  • Hi BrianCarp,

    I believe you have all the reasons for the confusion about how the editable policies (7 to 10) relate to the non-editable first 6 policies.

    I tried going through the signature sets of last 4 to look for how they relate or differentiate from the first 6, but with no luck.

    Please give me some time. I'll get in touch with the concerned people to have a comprehensive answer here. Rest assured - the documentation will definitely be updated accordingly.

    Regards,

    Dhiren  

  • Unknown said:
    Hi BrianCarp,

    I believe you have all the reasons for the confusion about how the editable policies (7 to 10) relate to the non-editable first 6 policies.

    I tried going through the signature sets of last 4 to look for how they relate or differentiate from the first 6, but with no luck.

    Please give me some time. I'll get in touch with the concerned people to have a comprehensive answer here. Rest assured - the documentation will definitely be updated accordingly.

    Regards,

    Dhiren  

    Any updates on this? I am also curious what the difference is between all the pre-defined IPS policies.

Reply
  • Unknown said:
    Hi BrianCarp,

    I believe you have all the reasons for the confusion about how the editable policies (7 to 10) relate to the non-editable first 6 policies.

    I tried going through the signature sets of last 4 to look for how they relate or differentiate from the first 6, but with no luck.

    Please give me some time. I'll get in touch with the concerned people to have a comprehensive answer here. Rest assured - the documentation will definitely be updated accordingly.

    Regards,

    Dhiren  

    Any updates on this? I am also curious what the difference is between all the pre-defined IPS policies.

Children
  • The Gui isn't easy, I took a number of attempts to un-select Microsoft Cabnet files names from the IPS policy System files which was effecting windows updates.

    I found that if you search for the name and the SID and use the column filters you can un-select the policy with out disturbing anything else.  I suggest just un-selecting the option then saving it ASAP.  The reason being scrolling through all 7000+ policies at 50 rows a shot is not easy to work with, also noticed that if you select the check box to select all, no all are selected.

    My 2 cents worth.

    feature request more intuitive GUI for managing IPS policies. 

    Still need to check if all are selected..