How to exclude a range of IPs from analysis with whitelists in RSA Web Threat Detection
Originally Published: 2015-08-20
Article Number
Applies To
RSA Product/Service Type: Forensics
RSA Version/Condition: All
Platform: Linux
Resolution
<whitelist
name="66.249.78.60"
and="32"
invisible="true"
/>
Here, the “and” attribute (which represents the CIDR mask bits) is 32 and so will correspond to a single IP address, but this value can be used to specify any range.
Example:
According to the whois for a particular IP:
$ whois 66.249.66.1 OrgName: Google Inc. OrgID: GOGL Address: 1600 Amphitheatre Parkway City: Mountain View StateProv: CA [Querying whois.internic.net] PostalCode: 94043 Country: US NetRange: 66.249.64.0 – 66.249.95.255 CIDR: 66.249.64.0/19 NetName: GOOGLE NetHandle: NET-66-249-64-0-1 Parent: NET-66-0-0-0-0 NetType: Direct Allocation NameServer: NS1.GOOGLE.COM NameServer: NS2.GOOGLE.COM Comment: RegDate: 2004-03-05 Updated: 2004-11-10
So using the CIDR for this you could filter all google IPs with a single entry of something like the following:
<whitelist
name="66.249.64.0"
and="19"
invisible="true"
/>
The cleanest/safest method to add these is within the Configuration Manager UI under schema but can also be added directly to the universal_conf.py, which would then need to be re-imported and pushed.
Notes
Related Articles
How to exclude files based on a regular expression in RSA Access Manager Agents 26Number of Views Delete a Trusted Realm 5Number of Views Enable a Trusted Realm 17Number of Views Trusted Realms 8Number of Views The display sequence of custom User Attribute Separators is incorrectly and unpredictably modified after making edits to U… 42Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager 8.9 Setup and Configuration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings.
Don't see what you're looking for?