11-07-2007 07:55 AM - edited 03-10-2019 03:51 AM
I'm experiencing what I believe to be a false positive on the BO2K-UDP (4055) signature. As near as I can tell, it is getting triggered by Xbox consoles when they connect to the Xbox Live! service. I am currently running the S307 sig update. What is the best way to report this to get it fixed?
Thanks,
Zach
11-14-2007 10:33 AM
Each signature has a section called Benign Trigger(s), you can use this to determine any false positives.In regards to IDS 5.0 modes refer to the following link:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dminter.htm
Other 5.0 documentation can be found at the link below:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/index.htm
12-25-2007 07:53 PM
I have encountered the BO2K alarm, after investigations, it is IPsec VPN traffic which triggers it.
you can tune the signature using IPS IDM.
If you have MARS, you have the option to create a false positive rule for it.
rgds
cash
12-31-2007 05:42 PM
I ran into this one too. After I looked at things, it is IPsec VPN traffic which triggered it. It was getting fired when traffic went to the outside interface of the PIX (not ASA). The PIX is also does remote user VPN traffic.
Mike
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide