Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to View IPS Rule IDs included in Default IPS Rules?

Having received a warning from Sophos regarding For CVE-2022-22963 we were advised to check that the IPS rule 2306989 is added to our policy.

Some of our rules use custom IPS policies, whereas others use the default ones, i.e. "LAN TO WAN" etc.

Having clicked into the Default options, it doesn't appear that you can then go into the individual categories and browse the included IPS rules. The custom IPS Policies do allow you to click into the individual setting and browse the rules and their associated ID's however.

Is there something I'm missing? It is dangerous to assume that this rule will already be included, and I'd like to be certain.

Many Thanks!



This thread was automatically locked due to age.
Parents
  • Hello Patrick,

    Thank you for contacting the Sophos Community.

    The CVE was addressed on the Signature Pack x.19.15.

    I am not sure though if you can check individually on each pre defined IPS rule, however for example each IPS has a Category, Severity, Platform, Target, 

    You could match the information on the signature

    and then go to the Predifined IPS and match, for example the WAN to LAN IPS, has the Web Service signatures enabled, and this one matches the Category server-other, which matches the IPS.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi Emmo,

    Thanks - is there a place within the XG interface where we can see which Signature Packs we have installed?

Reply Children