We received an ENS NIPS event saying clientA is port scanning clientB(Analyzer ID 3700). we want to exclude it. in the Exploit Prevention exclusion settings, I see we need to add a Signature ID for the exclusion, how can I find the Signature ID? thanks.
Hi @User21257322 To exclude clientA from port scanning clientB, edit the ENS Exploit Prevention policy assigned to clientB and add a Network IPS (NIPS) exclusion for clientA's IP address (e.g., 10.10.10.1 in the screenshot below). You can add the Signature ID if you wish to exclude the IP address for Signature 3700 specifically, otherwise leaving it blank excludes it from all NIPS signatures.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.