cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Threat Prevention Rules, Exceptions, Default Actions Precedence

L1 Bithead

I want to confirm the order of precedence for security profile rules, default actions, and exceptions.  For example, the default action for the SSH User Authentication Brute Force Attempt threat is alert.  However, the threat profile rule associated (simple-server-high) has an action of reset-both.  I think the rule action will override the default action of the signature meaning that the action of reset-both will be taken.  Is that correct?

 

As a follow up, in that scenario I also have exceptions for a few IPs with that use the default action of alert.  I think the exception will take precedence and the action will be to alert.  Is that correct?

 

To summarize, I think rules override the default action but exceptions override both the rules and original default action when an exception is enabled.  Is that correct? 

 

 

 

Who rated this post