We have several clients linking to our servers via applications, but some of these clients send different user-agents in the communication with the web server. The User's connection is then blocked and the firewall logs the following (using ip as an example): - All - all 2010-02-04 23:14:02 414 IDS Rule idp_lan Signature (user-agent.Generic.PHP.Injection)
I see that user-agent.Generic.PHP.Injection is part of the rule IPS_WEB_GENERAL which contains many signatures. Would it be possible to somehow ignore just user-agent.Generic.PHP.Injection or do I have to ignore the entire IPS_WEB_GENERAL rule?