IDS/IPS not logging blocked sites

IDS/IPS not logging blocked sites

IDS/IPS not logging blocked sites
IDS/IPS not logging blocked sites
Thursday - last edited Thursday
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.3.2

IDS/IPS not logging blocked sites

 

I have identified two websites that are being blocked when either IDS or IPS is enabled. During troubleshooting, I disabled IPS, and the sites started working as expected. Ultimately, I discovered that these sites are blocked in either IDS or IPS. Additionally, there are no corresponding entries in Insights > Threat Management, making the block difficult to trace.

 

us dot badgy dot com

sign dot rsign dot org

  0      
  0      
#1
Options
1 Reply
Re:IDS/IPS not logging blocked sites
Friday

  @smyles 

Thank you for your post. Could you let us know if you have made any other configuration changes on the router? If possible, please perform a mirror (port-mirror) packet capture while accessing these two websites with IDS/IPS disabled, so we can determine what is preventing access. Below is the mirror-capture guide—please take a look.

  0  
  0  
#2
Options