Simulated Blocking enables you to put the Sensor in a non-blocking mode whereby exploit attacks are not blocked even if the applied IPS policy is configured to do so. Alerts are still raised based on the configured policy. When Simulated Blocking is enabled, response actions that affect the flow of traffic, such as blocking, sending a TCP reset, and sending an ICMP host unreachable message, are not applied. This feature does not affect the Quarantine actions.
This feature allows an IPS sanity check where you get to know the specific attacks that would have hit a blocking rule, that is, which attacks would be blocked during normal operation without actually blocking them (the alerts explicitly mention that blocking has been simulated). You can also use this feature to temporarily disable blocking for troubleshooting.
Note
Simulated blocking applies to signature-based attack definitions only. Denial-of-Service and reconnaissance attacks will continue to activate response actions if configured to do so.
Simulated Blocking does not change the behavior of certain features of the Sensor. Further, these features will need to be disabled individually if required. The following list includes all such features:
DoS blocking
IP Reputation (formerly TrustedSource)
Firewall drop action
Host quarantine
IP sanity errors checks
You may choose to enable Simulated Blocking and configure the response action in your policy as a TCP Reset or ICMP Unreachable. In such instances, the Sensor does not carry out a designated response action; the Result column in the Attack Log displays one of the standard attack results, such as Attack Failed, Attack Successful, Attack Blocked, Inconclusive, or n/a. These attack result statuses are identical to those that are displayed when Simulated Blocking is disabled.
Note
Disable Simulated Blocking before performing an upgrade using the CLI. This allows data in the Manager to synchronize with the Sensor immediately after the upgrade. If not disabled, the first sigfile push will disable this option (by default it is disabled at device level).