Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Imperva Securesphere Blocking

    Posted 01-16-2024 02:32

    Hi Guys,

    I have created a custom DB Service rule to detect when Service accounts login from Local IP groups.

    When I set the action to block and test the same, imperva is not blocking the  login attempt. Any reason why?


    #DatabaseActivityMonitoring

    ------------------------------
    Eugene Wadeya
    SOC Team Lead
    Stima Sacco
    Nairobi
    ------------------------------


  • 2.  RE: Imperva Securesphere Blocking
    Best Answer

    Posted 01-16-2024 07:42

    Hi Eugene,

    Use the link below to check if the configured service account blocking settings are correct. 

    Blocking Traffic

    I hope this helps.



    ------------------------------
    Regards,
    𝐌𝐢𝐭𝐞𝐬𝐡 𝐌𝐞𝐡𝐭𝐚
    Senior Security Consultant
    Mumbai
    ------------------------------



  • 3.  RE: Imperva Securesphere Blocking

    Posted 01-16-2024 23:13

    Hi @Mitesh Mehta

    I followed all the instructions but the login is still successful.

    The MX sends an email alert when the policy is triggered but the login is not blocked. I tried both inline and sniffing mode, non is working



    ------------------------------
    Eugene Wadeya
    SOC Team Lead
    Stima Sacco
    Nairobi
    ------------------------------



  • 4.  RE: Imperva Securesphere Blocking

    Posted 01-17-2024 05:04

    Hi Eugene Wadeya,

    Could you please provide more details on how you can configure the service account's blocking settings.



    ------------------------------
    Regards,
    𝐌𝐢𝐭𝐞𝐬𝐡 𝐌𝐞𝐡𝐭𝐚
    Senior Security Consultant
    Mumbai
    ------------------------------



  • 5.  RE: Imperva Securesphere Blocking

    Posted 01-17-2024 20:57

    Hi Eugene,

    Please check below points might help. 
    1-Under policy do check if Action field is set to Block.
    2-Check relevant SecureSphere Agent on which you want to block traffic, Goto agent's Settings tab, enable the Blocking check box.
    3-Server Group mode is set to Active.

    Regards,

    Rakesh



    ------------------------------
    Rakesh Chinta
    Security specialist
    Synapxe Pte Ltd
    Singapore
    ------------------------------