This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Difference between "Action" (IPS policy rules) & "Recommended Action" (IPS signatures)

There is an action field found in both the IPS policy rules and the signatures that make up those rules.  Both fields have similar options (few more on the Rules side) which, per the Web manual, appear to have identical functions.

What is the difference here?

For example, let's say I have a rule set to Drop the Session but all of the signatures in that rule are set to Allow the Packets - what would happen?

Does one take precedence over the other?  If not, who wins?



This thread was automatically locked due to age.
Parents
  • Action
    Select an action to be taken from the available options:
    Available Options:
      Recommended: This action means that you want the OS to handle this alert level according to best-fit recommendations.
      Allow Packet: Allows the packet to its intended destination.
      Drop Packet: Drops packets if it detects any traffic that matches the signature.
      Disable: Disables the signature, if it detects any traffic that matches the signature.
      Drop Session: Drops the entire session if detects any traffic that matches the signature.
      Reset: Resets entire session if detects any traffic that matches the signature.
      Bypass Session: Allows the entire session if detects any traffic that matches the signature
Reply
  • Action
    Select an action to be taken from the available options:
    Available Options:
      Recommended: This action means that you want the OS to handle this alert level according to best-fit recommendations.
      Allow Packet: Allows the packet to its intended destination.
      Drop Packet: Drops packets if it detects any traffic that matches the signature.
      Disable: Disables the signature, if it detects any traffic that matches the signature.
      Drop Session: Drops the entire session if detects any traffic that matches the signature.
      Reset: Resets entire session if detects any traffic that matches the signature.
      Bypass Session: Allows the entire session if detects any traffic that matches the signature
Children
No Data