HTTP Unknown Tunnelling
I keep getting the following alert message multiple times a day.
Message meets Alert condition
The following intrusion was observed: "HTTP.Unknown.Tunnelling".
date=2016-01-25 time=09:57:21 devname=FG300C3912604135 devid=FG300C3912604135 logid=0419016384 type=ips subtype=signature level=alert severity=info srcip=172.20.215.138 dstip=54.165.70.151 srcintf="port2" dstintf="port3" policyid=10 identidx=0 sessionid=9877367 status=dropped proto=6 service=http count=1 attackname="HTTP.Unknown.Tunnelling" srcport=52029 dstport=80 attackid=107347981 sensor="default" ref="http://www.fortinet.com/ids/VID107347981" incidentserialno=1444277622 msg="http_decoder: HTTP.Unknown.Tunnelling,"
Should I be concerned and if NOT, how can I stop all this from hitting for review.
Thanks
Dee Dee
