This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS: FaceTime causes UDP flood

Is there anyway I can bypass the UDP flood protection for FaceTime?

Getting loads of the following in the IPS 

2016:02:11-14:11:15 xxxxxx ulogd[4503]: id="2105" severity="info" sys="SecureNet" sub="ips" name="UDP flood detected" action="UDP flood" fwrule="60013" initf="ppp0" srcip="xxxxxx" dstip="xxxxxx" proto="17" length="720" tos="0x04" prec="0x00" ttl="59" srcport="16402" dstport="16402"


This thread was automatically locked due to age.
Parents
  • I am an UTM 9 home user for 8 months now, and I am very impressed. 

     

    Sorry for bumping this old thread, but I had exactly the same and manage to add a exception the same way.

    Facetime is now working without lag or chopped sound and video so my exception in IPS is working.

    But my question is: Is it normal that this UDP flooding is still logged even after adding this exception? I would expect it to dissapear in the log.

    However it does dissapearsr in the log when I disable UDP flooding prevention. 

  • Hi and welcome to the UTM Community!

    There're likely more services you need to allow today beyond what Tim found back then.  You might try adjusting the Source/Destination packet rates instead of using an Exception.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Indeed there are - and it's 2x way with the exceptions too

     

    So you need: -

     

    Destination 16393:16402 / Source 1:65535 and another rule for

    Destination 1:65545 / Source 16393:16402

     

     

    Tim Grantham

    Enterprise Architect & Business owner

Reply
  • Indeed there are - and it's 2x way with the exceptions too

     

    So you need: -

     

    Destination 16393:16402 / Source 1:65535 and another rule for

    Destination 1:65545 / Source 16393:16402

     

     

    Tim Grantham

    Enterprise Architect & Business owner

Children