How do you achieve this?

You find a suspicious connection from a problematic host. You decide that you want to block
everything from that whole network, not just the problematic host. You want to block this for an
hour while you investigate further, but you do not want to add any rules to the Rule Base. How do
you achieve this?

You find a suspicious connection from a problematic host. You decide that you want to block
everything from that whole network, not just the problematic host. You want to block this for an
hour while you investigate further, but you do not want to add any rules to the Rule Base. How do
you achieve this?

A.
Use dbedit to script the addition of a rule directly into the Rule Bases_5_0.fws configuration file.
B. Select Block intruder from the Tools menu in SmartView Tracker.

C.
Create a Suspicious Activity Rule in SmartView Monitor.

D.
Add a temporary rule using SmartDashboard and select hide rule.



Leave a Reply 5

Your email address will not be published. Required fields are marked *


B4N3

B4N3

shouldn´t be answer B correct due to other questions on this sites?

Omar

Omar

I agree with b4n3

lukas

lukas

C)

block intruder is not possible to use for the whole subnet