Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dee_Dee
New Contributor

HTTP Unknown Tunnelling

I keep getting the following alert message multiple times a day.

Message meets Alert condition

The following intrusion was observed: "HTTP.Unknown.Tunnelling".

date=2016-01-25 time=09:57:21 devname=FG300C3912604135 devid=FG300C3912604135 logid=0419016384 type=ips subtype=signature level=alert severity=info srcip=172.20.215.138 dstip=54.165.70.151 srcintf="port2" dstintf="port3" policyid=10 identidx=0 sessionid=9877367 status=dropped proto=6 service=http count=1 attackname="HTTP.Unknown.Tunnelling" srcport=52029 dstport=80 attackid=107347981 sensor="default" ref="http://www.fortinet.com/ids/VID107347981" incidentserialno=1444277622 msg="http_decoder: HTTP.Unknown.Tunnelling,"

 

Should I be concerned and if NOT, how can I stop all this from hitting for review.

 

Thanks

Dee Dee

1 REPLY 1
ede_pfau
SuperUser
SuperUser

That depends on what you expect.

Apparently you have got an IPS signature 'default' in place and activated in a policy. So you are interested in detecting and/or blocking malicious traffic.

Tunneling traffic over a well-known port is common these days as an avoidance method. There's even tunneling over DNS (which is seldom protected). If you are concerned that there is traffic going in and out of your network without being inspected or being allowed then this IPS sensor is just the right tool.

The signature is blocking this kind of traffic right now. Unless you have reason to believe that this tunneling is officially permitted (depending on knowledge about your network) you better leave this in place.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors