<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Question on Default Action for Intrusion Protection Rule</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/101710/question-on-default-action-for-intrusion-protection-rule</link><description>I recently noticed some activity flagged as attacks on the XG Dashboard. Clicking on it indicated that the packets were allowed. I looked through the IPS policies to find the applicable rule, which was this one: Apple QuickTime traf Atom Out-Of-Bounds</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Question on Default Action for Intrusion Protection Rule</title><link>https://community.sophos.com/thread/369412?ContentTypeID=1</link><pubDate>Mon, 02 Apr 2018 08:12:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:60192941-411e-4066-bd25-fca586882836</guid><dc:creator>dma0</dc:creator><description>&lt;p&gt;Thank you MBP.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Question on Default Action for Intrusion Protection Rule</title><link>https://community.sophos.com/thread/369405?ContentTypeID=1</link><pubDate>Mon, 02 Apr 2018 06:03:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d40bc16e-26ff-4dd8-8d3f-e16ae9d52eba</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Just a small summery to this IPS Rule:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3668"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3668&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.snort.org/rule_docs/1-35860"&gt;https://www.snort.org/rule_docs/1-35860&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://telussecuritylabs.com/threats/show/TSL20150827-01"&gt;http://telussecuritylabs.com/threats/show/TSL20150827-01&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Its fixed since around about 2 years.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>