Solution for False Alarms and False Positives

Last Updated At: 2025-10-17 16:13:10

This topic describes how to deal with a large number of firewall false positives or an abnormal drop in traffic caused by improper strategy changes.


Problem

A large number of legitimate requests from certain IPs are blocked due to false positives in intrusion defense, or an abnormal traffic drop occurs because of improper strategy configuration.


Solution

If legitimate requests are blocked by Cloud Firewall, you can:

  • Disable the blocking feature temporarily
  • Allow requests from the affected IPs
  • Submit a support ticket to the Product Security Team for assistance

Steps

Step 1: Disable the Blocking Feature

  1. Log in to the Cloud Firewall Console.
  2. Click Intrusion Protection System in the left navigation pane.
  3. On the Intrusion Defense page, select Observe for the protection mode.
  4. Disable the “Enable Blocklist” option above the blocklist.

Step 2: Manual Troubleshooting

  1. Log in to the Cloud Firewall Console.
  2. Click Alert Management in the left navigation pane to open the Alert Management page.
  3. On the Alert Management page, select Blocked Statistics → Inbound.
  4. On the Inbound tab, choose Sort by Blocking Statistics to identify falsely blocked IP addresses.
  5. Add the falsely blocked IP addresses to the Allowlist using one of the following methods:

Method 1:

Click Allow on the right side of the falsely blocked IP address to add it to the Allowlist (Ignore List) and permit access.

Method 2:

On the Intrusion Defense page, select Ignore List → Add Addresses to add falsely blocked IP addresses in batches.

After these steps, restore the configuration made in Step 1 and monitor whether the traffic volume returns to normal.


Step 3: Submit a Ticket to Report False Positives

If the traffic volume remains abnormal after manual troubleshooting:

  1. Go to the Submit Ticket page.
  2. Provide your AppID and the falsely blocked IP addresses to the Security Team.
  3. The Security Team will review your case and adjust detection rules as necessary.
Note:

After you submit your report, the Security Team will respond within the specified timeframe and fine-tune intrusion defense rules based on the reported false positives.