cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
333
Views
0
Helpful
1
Replies

SNA - Removing false positives

Antonio Macia
Level 7
Level 7

We are getting alarms related to the "UDP Received" security event. After checking the flows, it is Microsoft Teams traffic the one triggering the security event. Is it possible to turno of this security event for traffic using a specific set of ports? I normally create role policies where I turn off alarming for the hostgroup or IPs causing the event, but in this case I want to keep the security event enabled to alarm for other traffic than Teams.

Regards. 

1 Reply 1

rschlayer
Level 6
Level 6

You could add the MS Teams Public IPs to a trusted outside hosts group for which you disable this alarm. Did you try that already?