Hello all,
Since yesterday I got a flood of our IPS about the following:
date=2024-10-10 time=09:55:22 devid="FG100XXXXXXXXXXXX" devname="100f_serverroom" eventtime=1728546922552439440 tz="+0200" logid="0419016384" type="utm" subtype="ips" eventtype="signature" level="alert" vd="root" severity="low" srcip=xxx.xx.xx.xx srccountry="Reserved" dstip=157.240.247.61 dstcountry="Netherlands" srcintf="VLAN72" srcintfrole="lan" dstintf="wan1" dstintfrole="wan" sessionid=1996577 action="dropped" proto=6 service="HTTP" policyid=6 poluuid="016585d8-cf8c-51ec-1bc2-98b96e341900" policytype="policy" attack="HTTP.Suspicious.Headers.With.Special.Characters" srcport=49694 dstport=5222 direction="outgoing" attackid=48934 profile="high_security" ref="http://www.fortinet.com/ids/VID48934" incidentserialno=168450119 msg="http_decoder: HTTP.Suspicious.Headers.With.Special.Characters" crscore=5 craction=32768 crlevel="low"
The destination is a meta-whatsapp service. This seems to happen with every message or interaction in WhatsApp that is made by a device.
It is interesting to note that this only started since I updated the version to 7.60 Build3401.
We have a Fortigate 100F
In order to prevent flooding, I wanted to deactivate logging specifically for the signature “HTTP.Suspicious.Headers.With.Special.Characters”, but unfortunately this does not work.
edit 2
set rule 48934
set log disable
set action pass
next
end
next
end
Thanks in advance
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Just a guess: The snippet shows "edit 2", implying that it may not be the only entry in that table. If there are more entries, make sure this one is moved to the top of the list/table, as the entries are actioned in top->down order.
Just a guess: The snippet shows "edit 2", implying that it may not be the only entry in that table. If there are more entries, make sure this one is moved to the top of the list/table, as the entries are actioned in top->down order.
Thanks, this was the issue.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.