Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS Pattern Updates and Existing Policies

When the XG device updates IPS patterns, under what circumstances will those updates be applied to existing policies\rules? If we do a 'search' for SMB in the IPS policy, select all and create a rule off that, will it be updated with new SMB patterns, or would we need to redo the search every update? Im thinking the latter, as the XG doesnt save search terms it appears. This makes 'tuning' IPS impossible, and we are stuck with all or nothing if you want current patterns. Is best case to grab categories? Which means, if I have a specific need with 3 signatures, i have to grab the entire category of 3000?



This thread was automatically locked due to age.
Parents Reply Children
  • If I'm not mistaken, this feature is coming in v17.  Alan posted a teaser in the v17 thread.  Here is the portion from his post that I believe would apply:

    "Here's another small teaser image. The new Smart Filter feature in IPS and App Control policies, allows dynamic selection of patterns by search terms. For example, if you're securing access to a sharepoint server, it's pretty trivial now, to use the smart filter, to dynamically select all sharepoint related attack patterns both now, and in future. You can do this statically today, but you would have to periodically edit your policy, and make sure to add any new patterns we may add, over time. This does that for you, automatically, every time there is a pattern update"

    Thanks,

    John

  • Nice catch,John. So the ideas should be marked as planned soon. Thanks.