Astaro Security Gateway Feature Requests Forum

43 votes

IPS: Per-Rule IPS Exceptions

Extended the exceptions functionality to allow for specific rules as part of an exception.

This will allow for much more granular IPS exceptions in being able to specify a rule be disable/excepted only for a certain traffic flow, like for rule 2122 from Internet to Webserver, without disabling t... more

  1. Comments
  1. It would be great if that was implemented. At the moment you have to disable a complete rule instead of just eliminating false positives apearing inside your own network. Also as Elmar stated the exceptions are a bit useless without the possibility to combine source and destination via AND.

  2. I think it is a duplicate post, there is also another request like this

  3. I agree, a v6 type configuration would be better that what's there now, but it needs to be flexible for new rules and edits to existing rules with the ability to revert an edited rule back to it's factory syntax.
    There should also be a way to fetch rules files from a central location. I'm not going to pretend to know the details of that methodology, but it seems doable.

  4. 3

    Yes, that`s what i need to! Astaro, give us this feature!!!

  5. 3

    I'm outta votes, but we do need a way to add our own rules, as we could in Version 6. I think the current method for managing the automatic ruleset is OK,but we need the ability to add custom rules again.

  6. ellell, do you mean you want to be able to write your own rules?

  7. 1

    I think it would be sufficient to change the "exceptions" dialogue the conjunction "source" and "destination network" from an "OR" to an "AND"

powered by UserVoice