Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dave
Explorer

IPS event - Syslog over non standard ports

Jump to solution

We have many of these events, and which i would want to get rid of.

Of course i can add an exception in IPS for this, but i would like to know if i can solve it first.

Also, how is this possible?

 

So our devices do send syslog over UDP 514, still the IPS events are triggered.

 

IPS.jpg

 

 

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

UDP/514 is the correct destination port for syslog traffic, but if I recall correctly the source port is supposed to be 514 as well and it is 57460 in your case which is causing the traffic be flagged by IPS.  Changing the source port to 514 on the sending system should resolve this.

If that is not feasible, there doesn't seem to be a way to add acceptable custom source ports to IPS for that syslog signature that I can see, so your best course of action here is probably an exception against this specific IPS signature for the sending server.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

2 Replies
Timothy_Hall
Champion
Champion

UDP/514 is the correct destination port for syslog traffic, but if I recall correctly the source port is supposed to be 514 as well and it is 57460 in your case which is causing the traffic be flagged by IPS.  Changing the source port to 514 on the sending system should resolve this.

If that is not feasible, there doesn't seem to be a way to add acceptable custom source ports to IPS for that syslog signature that I can see, so your best course of action here is probably an exception against this specific IPS signature for the sending server.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

Dave
Explorer

Hi Timothy,

I was under the impression that only the destination port had to match.

Thanks for your insight and info.

0 Kudos