- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-12-2020 09:57 PM - edited 08-12-2020 10:50 PM
What I am wanting to know is if I can add a range of IP addresses to a vulnerability exception.
This would be the entire 1-254 range, rather than 1 IP address at a time.
I have already checked the links below and they talk about adding IP addresses one at a time as an exemption.
Rather than allowing the vulnerability for the entire site, I would like to allow it for 192.168.1.0/24 for example.
08-13-2020 07:31 AM
Currently exemption is allowed only for single ip address not a subnet. Suggesting a workaround,
1)Clone the vulnerability profile and create the exemption ( without ipaddress)
2)create a new security policy with desired range, subnet as source and assign the new vulnerability profile ( cloned one).
Hope it helps.
Thanks,
Ram
08-13-2020 07:31 AM
Currently exemption is allowed only for single ip address not a subnet. Suggesting a workaround,
1)Clone the vulnerability profile and create the exemption ( without ipaddress)
2)create a new security policy with desired range, subnet as source and assign the new vulnerability profile ( cloned one).
Hope it helps.
Thanks,
Ram
08-14-2020 08:38 PM
The profile duplication and a new security rulebase entry is the best option as @RamprakashRT already mentioned if you are creating an exception for an entire subnet. I would really look at if you actually require an exception for an entire subnet though. Are you running into a false positive detection?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!