Webense 7.6 --> Filter IP subnet 192.168.0/24, but do not log it.

rated by 0 users
Answered (Not Verified) This post has 0 verified answers | 3 Replies | 2 Followers

Not Ranked
3 Posts
Charles Riley posted on 13 Oct 2011 1:59 PM

We have a situation where we need to filter traffic originating from 192.168.0.0/24, but we do not want to log it as this subnet is our "guest" network. 

 

While we need to filter the traffic (enforce our policies), we do not want or need to run reports on this subnet.

 

How would I accomplish this?

|

All Replies

Top 10 Contributor
446 Posts
Trusted Users (MVP)

what integration are you using? If you filter the traffic its not trivial not to log it. Why don't you want to log it?

|
Not Ranked
3 Posts

Thanks for your question/followup.  It is the "universal" integration.

The reason that we don't want to log this traffic is that since this is the "guest" subnet, we do not need or care about the individual users who use it.  Plus, we only see their IP addresses and not their details since these are all personally owned laptops.

 

That said, we are logging way too much info about these users, and that is consuming resources that are needed for logging users that we do need to run reports on.

 

 

|
Top 10 Contributor
2,443 Posts
Editor
Moderator
Suggested by J Sloan

the short answer of this issue is:  You can't.  If you filter it, it's going to be logged.

There are ways around it, but these are require more resources (additional firewalls, and another policy server/filter service for that public lan). 

There is no easy software only way of ignoring traffic specifically from one network range.

JACOB SLOAN, CCNA, WCSE

 

|
Page 1 of 1 (4 items)