Imperva Cyber Community

communities_1.jpg
 View Only
Expand all | Collapse all

No Alert triggered and no email received(followed action is set) when shifting from Simulation to Active Operation mode. But the user's IP address is blocked.

  • 1.  No Alert triggered and no email received(followed action is set) when shifting from Simulation to Active Operation mode. But the user's IP address is blocked.

    Posted 10-14-2022 22:34
    Hi Community,

    Does anyone experience the following?

    No Alert was triggered and no email was received(followed action is set) while on Active Operation mode.
    But the user's IP address is blocked.
    Simulation mode has no problem. An Alert was triggered, email was received.
    It only happens in MySQL DB Server.

    Thank you in advance for your input.
    #ImpervaAgent

    ------------------------------
    Marvin Tablizo
    Post Sales Team Lead
    M-Security Tech Philippines Inc.
    Makati City
    ------------------------------


  • 2.  RE: No Alert triggered and no email received(followed action is set) when shifting from Simulation to Active Operation mode. But the user's IP address is blocked.

    Posted 10-18-2022 17:07

    How is the IP being blocked? Is the action set to block at the policy level or you are assigning a followed action to do a long/short IP block ?

    What version are they running on the GW and MX?



    ------------------------------
    Sarvesh Lad
    Tech Lead @ On-Prem Managed Services (WAF, DAM, DRA & Sonar)
    ------------------------------