Table of Contents

ASN based IP Whitelisting

Rama Sadhu Updated by Rama Sadhu

Introduction

We maintain two databases: the Honeypot Database and the Criminal IP Database, both of which contain collections of malicious IPs. Through the Criminal IP Database, customers have the option to whitelist IPs based on their ASN.Ā 

An Autonomous System Number (ASN) is an identifier associated with a collection of IP addresses. When a customer chooses to whitelist, certain IPs based on their ASN, those IPs are allowed even if they are listed in a criminal IP database. As a result, the associated risk score may be disregarded. This practice helps reduce false positives.

Previously, we had made Criminal IP DB the default to all customers, this resulted in False Positives for some customers on Apptrana as Zscalar data center IPs are part of Criminal IP DB.
To ensure such FPs do not occur again, we have whitelisted all Zscalar IPs from Criminal IP DB check
This is done for all applications on AppTrana : Zscalar ASNs are whitelisted.

How to Whitelist Criminal/Malicious IP

  1. Go to Protect > Bot Protection > Policies > IP Reputation.
  2. Click on the Settings icon given.Ā 
  3. Select Criminal IP DB.Ā 
  4. Enter ASN name, click ADD, and then Save.
  5. Once the ASN is added, IPs associated with the ASN are whitelisted and ready for criminal DB check.

How did we do?

API Scan Coverage for OWASP Top 10

Advanced Behavioral DDoS

Contact

This site is protected by hCaptcha and its Privacy Policy and Terms of Service apply.