3 Replies Latest reply on Jul 1, 2013 11:52 AM by mtuma

    Ignore Blocked Traffic

      Hello all, I was hoping someone could help me solve a dilema I am having. I have a Sidewinder 8.3.1 on a network that has no internet connection. All of the traffic on this network is white listed. Many applications try to phone home for updates and various other things. For instance, Chrome is constantly trying to reach 74.125.0.0/16 . I have documented all of this traffic that is being blocked on my network that is still legitamate. Because the traffic is being blocked, it is constantly raising an alarm  for ACL Deny. I understand that I can just change my alarm thresholds, but that's not what I want to do. Does anyone know of a way that I can keep this traffic from raising an alarm? It would be great if I could somehow add to the alarms to ignore traffic to certain subnets. I thought I would check in here to see if anyone had any good ideas.

        • 1. Re: Ignore Blocked Traffic

          Hello,

           

          You should be able to create a new filter that will be used by the Attack Response for ACL DENY. Go into the Monitor>Audit Viewing section and right click on ACL DENY. Click create new filter and modify the filter section to show:

           

          event AUDIT_R_ACLDENY and not dst_ip 74.125.0.0/16

           

          Give it a name and then save. Go to the Attack Responses (under Monitor) and modify the ACL DENY one to use your new filter.

           

          -Matt

          • 2. Re: Ignore Blocked Traffic

            OMG mtuma, your my hero! I didn't even know this capability existed! Do all custom filters show up in the pouplated list of attack types when in Monior>Attack Responses?

            • 3. Re: Ignore Blocked Traffic

              >Do all custom filters show up in the pouplated list of attack types when in Monior>Attack Responses?

               

              They should yes. You just have to make sure you selected "Attack filter" when creating the filter (there is a radio button for that when creating the filter).

               

              -Matt