40031 Threat Exception

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

40031 Threat Exception

L4 Transporter

What I am wanting to know is if I can add a range of IP addresses to a vulnerability exception.

This would be the entire 1-254 range, rather than 1 IP address at a time.

 

I have already checked the links below and they talk about adding IP addresses one at a time as an exemption.

Rather than allowing the vulnerability for the entire site, I would like to allow it for 192.168.1.0/24 for example.

 

 
 
1 accepted solution

Accepted Solutions

L3 Networker

Hi @FarzanaMustafa 

 

Currently exemption is allowed only for single ip address not a subnet. Suggesting a workaround,

1)Clone the vulnerability profile and create the exemption ( without ipaddress) 

2)create a new security policy with desired range, subnet as source and assign the new vulnerability profile ( cloned one).

Hope it helps.

 

Thanks,

Ram

View solution in original post

2 REPLIES 2

L3 Networker

Hi @FarzanaMustafa 

 

Currently exemption is allowed only for single ip address not a subnet. Suggesting a workaround,

1)Clone the vulnerability profile and create the exemption ( without ipaddress) 

2)create a new security policy with desired range, subnet as source and assign the new vulnerability profile ( cloned one).

Hope it helps.

 

Thanks,

Ram

@FarzanaMustafa,

The profile duplication and a new security rulebase entry is the best option as @RamprakashRT already mentioned if you are creating an exception for an entire subnet. I would really look at if you actually require an exception for an entire subnet though. Are you running into a false positive detection? 

  • 1 accepted solution
  • 3080 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!