|
SID 480 - False Positive: msg#00203security.ids.snort.sigs
Rule: ICMP PING speedera Sid: 1:480 False Positives: The "Keep-Alive" feature enabled by default in many VPN Tunnels can trigger a false positive for this rule. Keep-alives make sure that a VPN tunnel stays established at all times by continuously sending ICMP pings through the tunnel. The tunnel is re-established if necessary. Nortel Instant Internet VPN devices have been observed generating ICMP traffic that is mis-interpreted by Snort as Speedera pings. ------------------------------- This is my first attempt to contribute to the Snort Rules database. I apologize if I have not used the proper format. Please let me know if I need to provide any additional information. Your feedback would be greatly appreciated to let me know this message made it's way to the right place. M.Firth ------------------------------------------------------- This Newsletter Sponsored by: Macrovision For reliable Linux application installations, use the industry's leading setup authoring tool, InstallShield X. Learn more and evaluate today. http://clk.atdmt.com/MSI/go/ins0030000001msi/direct/01/ |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: WEB-MISC SSLv3 invalid Client_Hello attempt: 00203, Vladimir Stavrinov |
|---|---|
| Next by Date: | RE: snort software: 00203, Naveen Kumar Akkugari |
| Previous by Thread: | Snort signatures for PBXi: 00203, Teicher, Mark |
| Next by Thread: | suggested changes to rule 2229: 00203, Rainer |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |