SRX

last person joined: 4 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  SRX IDP policy exeempt through firewall policy or through exemept rulebase

    Posted 03-09-2012 06:04

    Hi Experts

     

    I am inspecting the users zone to internal servers zone traffic through IDP policy for virus, worms etc. I want to exclude inspection for sharepoint server. Now I have two ways to do this:

     

    1- Make a specific firewall policy before the IDP enabled firewall policy from users zone to servers zone and just permit and not enable IPS

     

    2- I will make the exeempt rulebase in the IDP policy for the sharepoint

     

    What is the preferred and optimal method to do so?

     

    Thanks



  • 2.  RE: SRX IDP policy exeempt through firewall policy or through exemept rulebase

    Posted 03-09-2012 09:00

    Hi 

     

    Its more effective from performance perspective to exclude traffic

    from IDP processing completely (with firewall rule) then to process

    it in IDP and do exempts once the attack is found.



  • 3.  RE: SRX IDP policy exeempt through firewall policy or through exemept rulebase

    Posted 03-09-2012 11:06

    So my question is that if we have the facility to exlude the IPS inspection through firewall policy then why there is a need for exeempt rulebase in IPS?

     

    Thanks



  • 4.  RE: SRX IDP policy exeempt through firewall policy or through exemept rulebase
    Best Answer

    Posted 03-09-2012 11:34

    Exempt rulebase is mostly for fine-tuning your IDP policies. In particular,

    it allows to remove false positives that happen frequently from the logs.

     

    For example you see that between 1.1.1.1 and 2.2.2.2 an attack (say)

    HTTP directory traversal happens very often, and after investigation

    you decide that it is a false positive. You add the tuple

    1.1.1.1 - 2.2.2.2 - <This-attack-object>

    to the exempt database, and IDP does not catch these events anymore.



  • 5.  RE: SRX IDP policy exeempt through firewall policy or through exemept rulebase

    Posted 03-09-2012 14:33

    Thanks. It makes sense 🙂