Hi Everyone,
I found a policy attack: HTTP: Atlassian Confluence Server S Endpoint Information Disclosure Vulnerability. I have enabled blocking in IPS policy.
But I see in the attack log that its attack result is Inconclusive.
This means that the traffic has passed through the IPS, right?
How can I adjust the settings to protect my environment?
I also want to know, what situation does the Sensor consider it Inconclusive? Sometimes the same attack, the sensor can perform blocking?
My signature set version is up to date.
NSP model:NS-5100
NSP version: 10.1.5.75
Hello @User37794264
If the attack is inconclusive, it means the traffic passed and Sensor didn't take any action. You can enable blocking for specific signature from IPS Policy.
Hi
I have enabled block.
So I wonder why this result is happening and how can I deal with it.
Hello @User37794264
Please raise a support case to check this issue further.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA