• Lots of IPS attacks lately One CNC Trufflehunter cant find much info on it (False Positive?)

    StaffordFields
    StaffordFields
    We have been getting a LOT of IPS attacks lately. Getting Snort 38330 MALWARE-CNC TRUFFLEHUNTER SFVRT-1020 attack attempt from several internal IPs. Snort doesnt give much information.... is there a good chance these hosts are infected? Sophos Cloud AV…
    • Answered
    • over 8 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • DROWN Vulnerability: Blocking SSLv2 with UTM9

    scottsisco
    scottsisco
    Hello, I would like to write a firewall rule to drop all SSLv2 traffic attempting to travel through our UTM because of the DROWN vulnerability . We have a couple of servers susceptible to the attack and it would be nice to first block the attack at…
    • Answered
    • over 8 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • How to get details on 2 attacks blocked : rule 32488

    1RegularJoe
    1RegularJoe
    Hi, I had 2 attacks blocked, it is a bummer that I can't drill down on the actual text, but I found more detail in the "Network Protection" menu under "IPS: Top Blocked Attacks" I can figure out the host inside that tried to send the packet out…
    • over 8 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • View related content throughout UTM Firewall
  • More
  • Cancel