IBM Support

Firewall rule might not take configured action on Security Network IPS

Question & Answer


Question

Why does a firewall rule not affect any protocol as its configured in the policy?

Answer

When creating a Firewall rule on the Security Network IPS (GX) using the Any protocol, ensure that the ICMP Type All check box is disabled. If you enable this check box, it limits the rule to only ICMP and no other protocols. Clear this option if you want it to work for any protocol as specified in the screen capture below.



Note: If you are creating a firewall rule ignore TCP traffic, you must create two firewall rules for this to work properly; one rule specifies traffic that is destined to that IP address and a second rule for traffic that is sourced from that IP address.

[{"Product":{"code":"SS9SBT","label":"Proventia Network Intrusion Prevention System"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Policy","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"4.6.1;4.6.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
25 January 2021

UID

swg21685564