Task
-
Select
Analysis → <Admin Domain Name> → Attack Log.
The Attack Log page opens.
-
Select an alert to which you want to assign an ignore rule object and click
Other Actions → Create Exceptions → Add Ignore Rule.
The Add Ignore Rule window opens.
Tip
The Attack, Attacker, Target and Owner Domain are pre-populated with information about the alert.
- Enter a Name for the ignore rule and comment if required.
-
Select a
Secondary Action for the alert.
You can choose to acknowledge all alerts that match the rule or delete them.
-
You can add multiple attacks in the
Attack section and select the
Direction for the attacks.
If you want to assign the ignore rule to traffic leaving the network, select Outbound. If you want to assign the ignore rule to traffic entering the network, select Inbound. However, should you choose to assign the ignore rule to traffic in both directions, select Any.
Tip
You can enter the attack name to search the attack or select it from the Attack drop-down list and click Add.
-
Select the interface to which the rule has to be applied from the
Resource drop-down list and click
Add.
The scope of the ignore rule can be restricted to an interface or a device, or applicable to the admin domain as a whole.
-
Select or enter the
Attacker IP address from
Endpoint. You can add multiple
Attacker IP addresses.
You can also create a new rule object for the attacker by clicking the add icon. Click the edit icon to edit the selected IP address.
-
Select the
Port for the attacker IP address.
If you selected the port as TCP, UDP, or TCP or UDP, enter the port number.
- Select the Target IP address from Endpoint and the Port for the IP address.
-
Click
Save to save the ignore rule.
You can view the added ignore rule under Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Ignore Rules.