<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/utm-firewall/f/management-networking-logging-and-reporting/131793/ips-alerts---sid-57103---sophosupdate-exe-process</link><description>Hello guys, 
 I&amp;#39;m receiving a lot of IPS alerts with SID 57103 for diferent destination IPs. 
 2021:12:17-10:29:11 sg-alpex snort[25704]: id=&amp;quot;2101&amp;quot; severity=&amp;quot;warn&amp;quot; sys=&amp;quot;SecureNet&amp;quot; sub=&amp;quot;ips&amp;quot; name=&amp;quot;Intrusion protection alert&amp;quot; action=&amp;quot;drop&amp;quot; reason=&amp;quot;OS-WINDOWS</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/thread/485318?ContentTypeID=1</link><pubDate>Wed, 29 Dec 2021 15:11:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e506f06e-d8f3-4aff-b425-99f30035174e</guid><dc:creator>Fabio Canabarro</dc:creator><description>&lt;p&gt;Hello,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;After enabling update via HTTPS the alerts stopped, thanks!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/thread/484934?ContentTypeID=1</link><pubDate>Tue, 21 Dec 2021 14:38:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2277fc15-d63c-4cb7-aa2a-98a9ea1d9815</guid><dc:creator>Fabio Canabarro</dc:creator><description>&lt;p&gt;Hi, thanks for the reply!&lt;/p&gt;
&lt;p&gt;I&amp;#39;m testing the update change to HTTPS on these customers, but in parallel I&amp;#39;ll trigger Sophos support as suggested. Having an answer from them I share with you.&lt;/p&gt;
&lt;p&gt;Thanks again&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/thread/484933?ContentTypeID=1</link><pubDate>Tue, 21 Dec 2021 14:31:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c485cea4-4434-4717-b54b-ac06380b914f</guid><dc:creator>Fabio Canabarro</dc:creator><description>&lt;p&gt;I found in Sophos Central where to change the update option to HTTPS, in fact in this client it was set to HTTP. I changed it to HTTPS and I will monitor if IPS alerts stop.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Before:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/53/pastedimage1640096680259v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;After:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/53/pastedimage1640097048763v2.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;I will monitor and report the result.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/thread/484932?ContentTypeID=1</link><pubDate>Tue, 21 Dec 2021 14:14:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:78c299bb-1bac-4143-a9d9-e442e90a1f10</guid><dc:creator>Fabio Canabarro</dc:creator><description>&lt;p&gt;Hello, thanks for the reply!&lt;/p&gt;
&lt;p&gt;I checked the file you indicated, precisely in the UTM where I have these IPS alerts the UseHttps parameter is set to &lt;strong&gt;zero&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;UseHttps=0&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In other environments (completely separate Sophos Central and UTM customer) this option is set to 1.&lt;/p&gt;
&lt;p&gt;Do you know if this option is adjustable from Sophos Central? In the &lt;strong&gt;iconn.cfg&lt;/strong&gt; file there is an indication not to edit it directly, I don&amp;#39;t know if doing this will impact the endpoints.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/thread/484881?ContentTypeID=1</link><pubDate>Mon, 20 Dec 2021 20:42:47 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0368d43a-549a-48fa-a6b4-c83546567e63</guid><dc:creator>Sophos User930</dc:creator><description>&lt;p&gt;Out of interest, if you open:&lt;/p&gt;
&lt;p&gt;C:\ProgramData\Sophos\AutoUpdate\Config\iconn.cfg&lt;/p&gt;
&lt;p&gt;What is UseHttps set to?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS alerts - SID 57103 - SophosUpdate.exe process</title><link>https://community.sophos.com/thread/484849?ContentTypeID=1</link><pubDate>Mon, 20 Dec 2021 14:25:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b88a7ae5-e675-4322-bef8-93fae6505b8a</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Ol&amp;aacute; Fabio and welcome to the UTM Community!&lt;/p&gt;
&lt;p&gt;Excellent and thorough explanation of the situation.&amp;nbsp; I think this needs to have someone look at it - probably a 2nd- or 3rd-level engineer at Sophos Support as it involves both UTM and Intercept X.&amp;nbsp; Please share with us what they conclude.&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>