Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Best Practices for exclude the multiple schema user wrt source IP.

    Posted 20 days ago

    I have a query regarding user exclusion logic in Imperva DAM policies.

    Currently, we have separate security policies configured for each database server. In these policies, we are trying to exclude specific schema users based on source IP addresses.

    Our configuration approach is as follows:

    • For User, we are using the "At least" condition and specifying selected users.
    • For Source IP, we are using "Exclude all" and listing multiple IP addresses.

    For example:

    • Users: ABC, XYZ, STU, MNO
    • Source IPs: 0.1.0.1, 1.1.1.1, 2.2.2.2

    Our intention is to exclude only ABC and XYZ users when traffic comes from the specified IPs.

    However, in this setup, we observe that alerts are not triggered correctly. It seems that when multiple users and multiple IPs are configured together using this logic, the policy behavior becomes too broad, and unintended traffic may also get excluded or not evaluated as expected.

    In contrast, when fewer users/IPs are configured, it works as intended.

    Could someone help clarify:

    1. Why this behavior occurs when combining multiple users and multiple IPs with "At least" + "Exclude all" logic?
    2. What is the correct way to configure user-based exclusions with multiple IP conditions without impacting other users?
    3. Are there any best practices for structuring such exclusions in DAM policies?

    Any guidance or examples would be really helpful.


    #DatabaseActivityMonitoring

    ------------------------------
    Somnath Shinde
    Engineer

    ------------------------------


  • 2.  RE: Best Practices for exclude the multiple schema user wrt source IP.

    Posted 19 days ago

    Hi Somnath,

    Did you try to use IP Groups criteria (under Global Objects it can be defined) instead of adding individual/different IPs in Source IP Addresses of the security policy?

    Regards,



    ------------------------------
    SBISOC 4430
    Manager
    Mumbai
    ------------------------------