How to exclude a range of IPs from analysis with whitelists in RSA Web Threat Detection
Originally Published: 2015-08-20
Last Modified: 2022-06-20
Article Number
Applies To
RSA Product/Service Type: Forensics
RSA Version/Condition: All
Platform: Linux
Resolution
<whitelist
name="66.249.78.60"
and="32"
invisible="true"
/>
Here, the “and” attribute (which represents the CIDR mask bits) is 32 and so will correspond to a single IP address, but this value can be used to specify any range.
Example:
According to the whois for a particular IP:
$ whois 66.249.66.1 OrgName: Google Inc. OrgID: GOGL Address: 1600 Amphitheatre Parkway City: Mountain View StateProv: CA [Querying whois.internic.net] PostalCode: 94043 Country: US NetRange: 66.249.64.0 – 66.249.95.255 CIDR: 66.249.64.0/19 NetName: GOOGLE NetHandle: NET-66-249-64-0-1 Parent: NET-66-0-0-0-0 NetType: Direct Allocation NameServer: NS1.GOOGLE.COM NameServer: NS2.GOOGLE.COM Comment: RegDate: 2004-03-05 Updated: 2004-11-10
So using the CIDR for this you could filter all google IPs with a single entry of something like the following:
<whitelist
name="66.249.64.0"
and="19"
invisible="true"
/>
The cleanest/safest method to add these is within the Configuration Manager UI under schema but can also be added directly to the universal_conf.py, which would then need to be re-imported and pushed.
Notes
Related Articles
How to exclude files based on a regular expression in RSA Access Manager Agents 26Number of Views Activity Node Excludes Previous Approvers Without Exclusion Settings in RSA Governance & Lifecycle 6Number of Views How to configure SNMP for RSA Authentication Manager 8.x 1.31KNumber of Views AADSTS50107: Requested federation realm object 'http:/<Identity Router FQDN>/' does not exist when trying to access the Mi… 64Number of Views Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service 102Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?