A firewall policy or access control list (ACL) is used to control host access by specifying attacker and target. You can create and assign advanced firewall policies using the Ignore Rules page.
Select Analysis → <Admin Domain Name> → Attack Log.
The Attack Log page opens.
Select an alert to which you want to assign an ignore rule object and click Other Actions → Create Exceptions → Add Ignore Rule.
The Add Ignore Rule window opens.
Tip
The Attack, Attacker, Target and Owner Domain are pre-populated with information about the alert.
Enter a Name for the ignore rule and comment if required.
Select a Secondary Action for the alert.
You can choose to acknowledge all alerts that match the rule or delete them.
For an ACL remove the attack. You can remove the attack by clicking the X icon.
Select the interface to which the rule has to be applied from the Resource drop-down list and click Add.
The scope of the ignore rule can be restricted to an interface or a device, or applicable to the admin domain as a whole.
Select or enter the Attacker IP address from Endpoint. You can add multiple Attacker IP addresses.
You can also create a new rule object for the attacker by clicking the add icon. Click the edit icon to edit the selected IP address.
Select the Port for the attacker IP address.
If you selected the port as TCP, UDP, or TCP or UDP, enter the port number.
Select the Target IP address from Endpoint and the Port for the IP address.
Click Save to save the ignore rule.
You can view the added ignore rule under Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Ignore Rules.