<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Protocol Violation alerts in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-Violation-alerts/m-p/96946#M10407</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;We are getting Protocol Violation alerts with our Remote access client users that are running Jabber SIP Clients --&amp;nbsp;Firewall - Protocol violation detected with protocol:(RTP), matched protocol sig_id:(1), violation sig_id:(9). (500). It looks to me like this is the RTP voice traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is this traffic not matching the protocol signature for RTP Voice and how do we fix issues like this? I have a few other protocol violation alerts too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The traffic is allowed so phone calls are working fine but we shouldn't be getting these alerts.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Sep 2020 12:53:00 GMT</pubDate>
    <dc:creator>JoeSt89</dc:creator>
    <dc:date>2020-09-17T12:53:00Z</dc:date>
    <item>
      <title>Protocol Violation alerts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-Violation-alerts/m-p/96946#M10407</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;We are getting Protocol Violation alerts with our Remote access client users that are running Jabber SIP Clients --&amp;nbsp;Firewall - Protocol violation detected with protocol:(RTP), matched protocol sig_id:(1), violation sig_id:(9). (500). It looks to me like this is the RTP voice traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is this traffic not matching the protocol signature for RTP Voice and how do we fix issues like this? I have a few other protocol violation alerts too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The traffic is allowed so phone calls are working fine but we shouldn't be getting these alerts.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 12:53:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-Violation-alerts/m-p/96946#M10407</guid>
      <dc:creator>JoeSt89</dc:creator>
      <dc:date>2020-09-17T12:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol Violation alerts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-Violation-alerts/m-p/97136#M10408</link>
      <description>&lt;P&gt;To fix the underlying issue you'll probably need packet captures and a TAC case.&lt;BR /&gt;You can also not use the relevant services in the service column, thus not activate the relevant protocol parsers, but that's a less secure option.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 05:14:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-Violation-alerts/m-p/97136#M10408</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-21T05:14:10Z</dc:date>
    </item>
  </channel>
</rss>

