I integrate Mcafee NSP with GTI IP Reputation, i can test some IP Reputation. Now i'm trying to block High Risk IP Reputation but i don't see any Attack related to GTI IP Reputation on IPS policy to configure Block these High Risk IP Reputation. Does anyone have any idea on this case?
Thanks and Regards!
You can create a connection limiting policy based on GTI file reputation and block or limit connections from High Risk IP addresses.
I don't have an NSM UI at hand now, but maybe NTBA policies have some signatures to alerts on comms with bad IP reputation, or maybe you can configure host communication rules to alert (not block) on these too.