cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1127
Views
5
Helpful
5
Replies

Our security systems detect a network attack from your server - Web Security Appliance S170.

its
Level 1
Level 1

Our security systems detect a network attack from your server. Web Security Appliance S170
On our internal domain controllers on port 445 (TCP). What could be the reason for this behavior and why this particular port of the Web Security Appliance S170?

5 Replies 5

Tao Yang
Cisco Employee
Cisco Employee

In general, WSA needs to connect to the configured AD servers over port 445 for proxy authentication.  Enable surrogate in WSA identity setting could normally reduce such connections.

What is meant by "Enable surrogate in WSA identity setting could normally " ?  Timeout change (see pic.) ?  Or other settings via SSH ?

Increasing this parameter did not help. Maybe there are other suggestions?

Thank you

Tao Yang
Cisco Employee
Cisco Employee

It is in WSA Identity settings>Authentication Surrogates.

Hey this should be the answer  - 

Your security system is likely flagging a FP for an attack from the S170's IP address because the WSA is sending traffic over port 445 at high rates to authenticate your users. 

As a suggestion -

1)I would run the cli command 'testauthconfig' to confirm my S170 utilizes netbios

2)whitelist port 445 from the security sensor 

Please let me know if I have answered your question or if you have additional questions.

Best,

Peter