Which category contains the filter for Log4shell?

Hi all, which category should I enable on the "Webserver Protection", "Firewall Profiles", "Common Threat Filter Categories" to block log4j related attacks?

Thanks for any help!!

  • I thought these were already being blocked by snort rules?  According to the IPS rule sheet the snort SIDs are there. So wouldn't the rule be applied no matter which you would choose?

  • Hi Amodin, so to understand well, the snort rules are the default ones already integrated in the IPS filter and that regardless of the categories that I can choose in the WAF filter, they will always be applied and cannot be disabled, is that correct?

