Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Exclude the traffic coming from specific website from IPS check

Hello, I installed XG Firewall Home Edition last month and I'm enjoy studying it now.
I have a question about the exception for IPS.

Is there any way to exclude the traffic between a specific website and LAN from IPS check?
I don't want to remove the detected signature itself, because it becomes Firewall will not check the signature from the other sites in the world.
If possible, excluding the traffic coming from a specific website only for a specific signature is the best.

What I tried was adding 2 x Custom IPS Signatures as below, but it didn't help.
------------------------
One was
 Custom Rule: srcaddr:211.13.196.161;
 Severity: Minor or Warning
 Recommended Action: Allow Packet or Bypass Session
Second was
 Custom Rule: dstaddr:211.13.196.161;
 Severity: Minor or Warning
 Recommended Action: Allow Packet or Bypass Session

I created an IPS Policy Rule for 2 x Custom IPS Signatures(the Action was Recommended or Allow Packet or Bypass Session) and put the added IPS Policy to the top order of the IPS Policy which was set in my Firewall Policy.
------------------------

Thanks in advance.



This thread was automatically locked due to age.