Scenario
To find the root cause of cases for IPS alerts in the Attack Log page that shows wrong country name for Attacker and Target.
Problems type to be solved
The Attack Log page displays wrong country name for source or destination IP address for an IPS alert.
Troubleshooting Steps
Applicable to Sensor models: NS-series and Virtual IPS Sensors
Sensor software versions: 10.1.5.116 and later for NS-series Sensors, and 10.1.7.86 and later for Virtual IPS Sensors
Download the latest signature set and deploy it to the Sensor.
This ensures that the Sensor has the latest Digital Envoy database and country-to-CIDRs mapping information.
Login to the Sensor with “admin” ID.
In the Sensor CLI, issue the
debugcommand to enter Debug mode.In Debug mode, type the following command and press Enter:
show geoloc ipv4 <IP Address>The Sensor CLI returns the latest country information for the specified IP address. If you think the information is incorrect, contact Support for further assistance.
Note
If the Manager and Sensor are on software versions prior to 10.1 Update 7, it is recommended to upgrade them to later versions to continue receiving the updated geolocation databases. For more information, refer to KB95636. Always ensure to maintain the latest software versions of the Manager, Sensor, and Signature Sets.