Description

In some environments, the firewall may drop traffic on an IDP rule that references a custom attack group, even when the matched signature is not part of that custom attack group.

This behavior can be seen after changing an IDP rule action from no-action to drop-packets or recommended. It is most commonly observed in deployments where multiple LSYS instances use the same IDP configuration, including the same custom attack group name.

Symptoms

You may observe one or more of the following:

  • Traffic is dropped by an IDP rule unexpectedly.
  • Logs show signature matches that are not included in the referenced custom attack group.

Solution

Use a unique custom attack group name for each LSYS. This workaround prevents unintended signature matching across LSYS instances and stops the firewall from incorrectly dropping traffic due to IDP policy evaluation.

Modification History

2024-11-16 : Article Created