How to exclude a range of IPs from analysis with whitelists in RSA Web Threat Detection
Originally Published: 2015-08-20
Article Number
Applies To
RSA Product/Service Type: Forensics
RSA Version/Condition: All
Platform: Linux
Resolution
<whitelist
name="66.249.78.60"
and="32"
invisible="true"
/>
Here, the “and” attribute (which represents the CIDR mask bits) is 32 and so will correspond to a single IP address, but this value can be used to specify any range.
Example:
According to the whois for a particular IP:
$ whois 66.249.66.1 OrgName: Google Inc. OrgID: GOGL Address: 1600 Amphitheatre Parkway City: Mountain View StateProv: CA [Querying whois.internic.net] PostalCode: 94043 Country: US NetRange: 66.249.64.0 – 66.249.95.255 CIDR: 66.249.64.0/19 NetName: GOOGLE NetHandle: NET-66-249-64-0-1 Parent: NET-66-0-0-0-0 NetType: Direct Allocation NameServer: NS1.GOOGLE.COM NameServer: NS2.GOOGLE.COM Comment: RegDate: 2004-03-05 Updated: 2004-11-10
So using the CIDR for this you could filter all google IPs with a single entry of something like the following:
<whitelist
name="66.249.64.0"
and="19"
invisible="true"
/>
The cleanest/safest method to add these is within the Configuration Manager UI under schema but can also be added directly to the universal_conf.py, which would then need to be re-imported and pushed.
Notes
Related Articles
How to exclude files based on a regular expression in RSA Access Manager Agents 26Number of Views Duplicate Local Entitlements may occur when Provisioning Local Entitlements through Manual Activities in RSA Identity Gove… 28Number of Views How to exclude RSA Authentication Manager 8.x from picking up disabled user account data from the Microsoft LDAP directory 171Number of Views Activity Node Excludes Previous Approvers Without Exclusion Settings in RSA Governance & Lifecycle 3Number of Views Is RSA AA compliant with Federal Act 508 54Number of Views
Trending Articles
RSA Authentication Manager Patch Updates RSA SecurID Software Token 4.1.2 and 4.2.1 for Mac OS X displays: No token storage device was detected. Verify that the de… How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Configuring a Checkpoint firewall to work with SecurID
Don't see what you're looking for?