Hi Heroes,
We received an ENS NIPS event saying clientA is port scanning clientB(Analyzer ID 3700). we want to exclude it. in the Exploit Prevention exclusion settings, I see we need to add a Signature ID for the exclusion, how can I find the Signature ID? thanks.
Hi,
Analyzer ID 3700 refers to TCP Port Scan.
You can try the same ID for Signatures ID.
Let us know how it goes.
Thanks
Thanks, btw if I only want to exclude clientA port scanning clientB, May I know how can I define the exclusion? should I just enter the ip address of both clientA and clientB?
Hi @User21257322 To exclude clientA from port scanning clientB, edit the ENS Exploit Prevention policy assigned to clientB and add a Network IPS (NIPS) exclusion for clientA's IP address (e.g., 10.10.10.1 in the screenshot below). You can add the Signature ID if you wish to exclude the IP address for Signature 3700 specifically, otherwise leaving it blank excludes it from all NIPS signatures.
Ref https://docs.mcafee.com/bundle/endpoint-security-10.7.x-common-product-guide-windows/page/GUID-03008... in the Product Guide.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA