Skip to main content
tanr
New Member
September 5, 2018
Question

IPS logs with Attack ID 0 and Attack Name Unknown?

  • September 5, 2018
  • 5 replies
  • 10216 views

I'm seeing some IPS logs for outbound connections that show no ID or name, like so:

 

Attack Name Unknown Attack ID 0 Reference https://fortiguard.com/encyclopedia/ips/0

Message : ,

Event Type signature

Protocol Number 6

Type utm

Sub Type ips

 

Destination 

IP 52.162.166.27 Host Name client-s.gateway.messenger.live.com Port 443 Destination Interface Hostname ch1-client-s.gateway.messenger.live.com URL          ch1-client-s.gateway.messenger.live.com Application Protocol tcp Service P2P

 

Action detected

 

Any ideas what might be going on?  

    5 replies

    tanr
    tanrAuthor
    New Member
    September 5, 2018

    Forgot to add: FortiOS 5.6, Extended IPS database.

     

    It is showing that it's using one of my specific IPS profiles, but the only P2P application listed within that profile has a proper ID.

    Aleksandr_Avdiuhskin
    New Member
    September 6, 2018

    Hi Tanr,

    I have found same message from my reporting system.

     

    attackid=0 ref="http://www.fortinet.com/ids/VID0"

     

    Regards,

    pal_FTNT
    Staff
    Staff
    September 6, 2018

    It's a known issue and the developers are already looking into it. 

    tanr
    tanrAuthor
    New Member
    September 7, 2018

    Thanks for the update.  Is there a bug number to track this?

    pal_FTNT
    Staff
    Staff
    September 7, 2018

    510539

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.