Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to create an exception for a site that I am getting an INDICATOR-COMPROMISE Suspicious .pw error

I am trying to access a site and I am getting an error in the Intrusion Prevention System (Live Log).   I tried to create an exception with the IP of the website I am trying to access but that does not work.   It works when I disable IPS.  I am running a Home Sophos UTM9, Firmware version 9.409-9.

 

Any suggestions

 

Thanks

Brian

 

 



This thread was automatically locked due to age.
Parents Reply
  • "DNS query" was the missing detail, Brian.  There are some top-level domains (TLDs) that are known to be used primarily for nefarious activities, so Advanced Threat Protection flags the DNS query and this block is reported in the Intrusion Prevention log.  I suspect that you could have disabled ATP instead of Snort and then been able to do the DNS query.

    Google tld pw and you will see what the problem is.  The domain vector.pw has now been completely removed and is no longer available for registration.  If your PC or UTM still has an IP for that, you can see where it is at http://www.ip2location.com/demo.

    Most people prefer to Block a TLD when they get this warning.

    Cheers - Bob

Children