Description

This article gives explanation of why don’t you see any attack object/attacks in some of the predefined attack groups.

Symptoms

Attack object/attacks are not displayed in some of the predefined attack groups.
The following screenshot for NSM which shows "VOIP - Critical" predefined group which shows no attack member.


alt

Solution


Some of the attack groups do not have any group members; they are made for future use. In the future, when predefined attacks are defined in their respective categories, these attack groups will be updated to the device.

This applies to all the devices with the IDP feature such as Standalone IDP, ISG-IDP and SRX-IDP.

Groups such as "Critical - VOIP” and “Critical - ICMP” do not have any members as of now.



If you want to check the policy/components of that particular attack group from the CLI

STANDALONE IDP:

[root@defaulthost ~]# less /usr/idp/device/state/s0/policy.set


SRX - IDP:

root% less /var/db/idpd/sets/ <policy-name> .set



SRX - ISG:

There is not an equivalent CLI command.  Use the NSM GUI.