- The IPs being blocked are in fact showing reputations so I guess I would have to say they are being blocked appropriately if I thought about it. I say they are valid connections because its one of our consultants emailing that they are being blocked. We have over 60k consultants though, so, maybe its the case that when it was setup, malicious detection should not have been enabled.
2. As stated above, they are flagged by bright cloud so they are actually being blocked correctly according to our policy.
3. No one is left that was involved, the only thing I am aware of is we were having trouble with bots and sql injections attempts. I am not aware that we needed the malicious setting enabled, I was just trying to leave as much security in place as I could but make it work the best way possible.
With that. said, I am going to disable the malicious blocking and see how things go. I am new to ASM and I wasn't aware how much learning/tweaking is really possible if bright cloud is detecting an issue...
If I leave the malicious blocking disabled, what is the best method or view in ASM to monitor to know if its becoming an actual issue in the future?
Thank you again in advance for walking through this, it was handed to me by default and I am working on getting into some ASM training to help make sure things are correct.