I keep getting the following alert message multiple times a day.
Message meets Alert condition
The following intrusion was observed: "HTTP.Unknown.Tunnelling".
date=2016-01-25 time=09:57:21 devname=FG300C3912604135 devid=FG300C3912604135 logid=0419016384 type=ips subtype=signature level=alert severity=info srcip=172.20.215.138 dstip=54.165.70.151 srcintf="port2" dstintf="port3" policyid=10 identidx=0 sessionid=9877367 status=dropped proto=6 service=http count=1 attackname="HTTP.Unknown.Tunnelling" srcport=52029 dstport=80 attackid=107347981 sensor="default" ref="http://www.fortinet.com/ids/VID107347981" incidentserialno=1444277622 msg="http_decoder: HTTP.Unknown.Tunnelling,"
Should I be concerned and if NOT, how can I stop all this from hitting for review.
Thanks
Dee Dee
That depends on what you expect.
Apparently you have got an IPS signature 'default' in place and activated in a policy. So you are interested in detecting and/or blocking malicious traffic.
Tunneling traffic over a well-known port is common these days as an avoidance method. There's even tunneling over DNS (which is seldom protected). If you are concerned that there is traffic going in and out of your network without being inspected or being allowed then this IPS sensor is just the right tool.
The signature is blocking this kind of traffic right now. Unless you have reason to believe that this tunneling is officially permitted (depending on knowledge about your network) you better leave this in place.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.