FAQs : NetScaler Application firewall : IP Reputation

FAQs : NetScaler Application firewall : IP Reputation

book

Article ID: CTX217543

calendar_today

Updated On:

Description

Q. What is IP Rep and how does it Work?
A. IPREP is a new feature on Netscaler 11.0 onwards which uses a 3rd party dynamic database to allow/restrict the traffic into your network, based on the IP Reputation provided by BrightCloud for the Source IP's.

Q. How is this database downloaded to NS?
A. Once the reputation feature is enabled, the NetScaler Webroot database is downloaded. 
The iprep process connects with Webroot and updates the database every 5 minutes.

This DB is downloaded from *api.bcss.brightcloud.com:443* which is hosted on Amazon cloud.
Hence your NS should be able to resolve this name into an ip using DNS and required firewall rules should be there to allow this traffic.

Q. Is there any Version of IPREP Database?
A. The Webroot database major version is currently version: 1.
The minor version gets updated every day.  The update version is incremented after every 5 minutes and is reset back to 1 when the minor version is incremented.

Q. How are IP Addresses Stored in the Database?
A. The IP addresses in the database are in decimal notation.