Help Center/ Cloud Firewall/ FAQs/ Troubleshooting/ What Do I Do If IPS Blocks Normal Services?
Updated on 2024-07-31 GMT+08:00

What Do I Do If IPS Blocks Normal Services?

If normal service traffic is intercepted, perform either of the following operations:

Querying Hit Rules and Modifying Protection Actions

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed.
  4. (Optional) Switch firewall instance: Select a firewall from the drop-down list in the upper left corner of the page.
  5. In the navigation pane, choose Log Audit > Log Query. Click the Attack Event Logs query and record the Rule ID of the rule that blocks traffic.

    Figure 1 Rule ID

  6. In the navigation pane, choose Attack Defense > Intrusion Prevention. Click View Effective Rules under Basic Protection. The Basic Protection tab is displayed.
  7. Search for the rule by its ID. In the Operation column, change its action to Observe or Disable.

    • Observe: The firewall logs the traffic that matches the current rule and does not block the traffic.
    • Disable: The firewall does not log or block the traffic that matches the current rule.