<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: http method not recognized and ntlm authentication in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698727#M87842</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The signatures that fire are 12674 and 12676&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Jan 2007 10:41:41 GMT</pubDate>
    <dc:creator>rnaydenov</dc:creator>
    <dc:date>2007-01-10T10:41:41Z</dc:date>
    <item>
      <title>http method not recognized and ntlm authentication</title>
      <link>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698725#M87838</link>
      <description>&lt;P&gt;Does anybody know why ips signatures fire on ntlm authentication proxy? In our environment we have ISA 2004 and the ips is complaining about http not in rfc specs and http not recognized. Is it possible that ips does not understand ntlm proxy authentication?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698725#M87838</guid>
      <dc:creator>rnaydenov</dc:creator>
      <dc:date>2019-03-10T10:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: http method not recognized and ntlm authentication</title>
      <link>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698726#M87840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you send me what signatures are firing and a traffic sample that is causing the issue?  The sensor understands SMB and MSRPC, but does not do MSRPC over HTML and I wonder if your proxy authentication is implemented this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Cothrell&lt;/P&gt;&lt;P&gt;Cisco IPS Dev Team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jan 2007 17:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698726#M87840</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2007-01-09T17:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: http method not recognized and ntlm authentication</title>
      <link>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698727#M87842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The signatures that fire are 12674 and 12676&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jan 2007 10:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698727#M87842</guid>
      <dc:creator>rnaydenov</dc:creator>
      <dc:date>2007-01-10T10:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: http method not recognized and ntlm authentication</title>
      <link>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698728#M87843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These signatures are policy enforcement signatures.  They are firing because the AIC engine has determined that the NTLM proxy application is running a non-web http based protocol on a web port.  That will trigger 12674.  12676 is triggered when there is an HTTP request method being seen that is not in the list of acceptable HTTP request methods (listed in 12676 config).  Currently, the method list should be considered static, even though it appears that you can add to this list, there are known issues that make updating it unreliable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd look at the alarms to see if either the attacker or victim address is constant.  I'm not sure how it will fire, but if one side is consistently the ISA system, then you can probably implement an alarm channel filter to keep those two signatures from firing with the ISA as the attacker/victim.   Personally, I'd consider disabling the signatures since they are not compatible with your network policy.&lt;/P&gt;&lt;P&gt;WRT to tuning 12676, the entire AIC engine is being actively worked on to improve its robustness and functionality, though no specific release vehicle has been determined--yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jan 2007 14:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-method-not-recognized-and-ntlm-authentication/m-p/698728#M87843</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2007-01-10T14:53:31Z</dc:date>
    </item>
  </channel>
</rss>

