Skip to main content

Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

Loading...
Loading...

INFO: How do I troubleshoot pattern over-blocking issues?

Expand / Collapse


This article applies to:

  • R3000/WF/WFR

Question:

How do I troubleshoot pattern over-blocking?

Reply

Due to the nature of pattern based filtering, some overblocking or false-positives can occur. Pattern filtering takes precedence over normal library filtering rules, so adding the site/IP to an Allow category will not stop pattern detection from blocking the request.

However, if you know the IP address that is triggering the block you can do this:

1.Admin control of pattern filtering Whitelist for R3000 Software Version 3.0.00.9 or Higher: The new Pattern Detection Whitelist window (Library > Pattern Detection Whitelist) lets you create a list of IP addresses that will always bypass pattern detection filtering.

Only the IP is needed not any ports or http://


This article was previously published as:
8e6 KB 300025

To contact LevelBlue about this article or to request support:


Rate this Article:
     
Tags:

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.