This article explains how to disable 'Action: Ignore' logs for the vNTD Segment IP in Corero.
During the incident, multiple 'Action: Ignore' logs were generated for the vNTD segment IP address, as observed in the Corero mitigation dashboard.
To disable 'Action: Ignore' logs for the vNTD Segment IP, update the CIDR Rule Policy configuration as follows:
1) Go to SWA Application → Mitigation → CIDR Rule Policy.
2) Click Edit, then set the action to Disabled for the relevant CIDR Rule Policy entry.
3) Refer to the table below for a comparison of actions supported by CIDR Rule Policy and Service Level Policy across different router types:
limit_100000