Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dave
Contributor
Jump to solution

IPS event - Syslog over non standard ports

We have many of these events, and which i would want to get rid of.

Of course i can add an exception in IPS for this, but i would like to know if i can solve it first.

Also, how is this possible?

 

So our devices do send syslog over UDP 514, still the IPS events are triggered.

 

IPS.jpg

 

 

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

UDP/514 is the correct destination port for syslog traffic, but if I recall correctly the source port is supposed to be 514 as well and it is 57460 in your case which is causing the traffic be flagged by IPS.  Changing the source port to 514 on the sending system should resolve this.

If that is not feasible, there doesn't seem to be a way to add acceptable custom source ports to IPS for that syslog signature that I can see, so your best course of action here is probably an exception against this specific IPS signature for the sending server.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

2 Replies
Timothy_Hall
Legend Legend
Legend

UDP/514 is the correct destination port for syslog traffic, but if I recall correctly the source port is supposed to be 514 as well and it is 57460 in your case which is causing the traffic be flagged by IPS.  Changing the source port to 514 on the sending system should resolve this.

If that is not feasible, there doesn't seem to be a way to add acceptable custom source ports to IPS for that syslog signature that I can see, so your best course of action here is probably an exception against this specific IPS signature for the sending server.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
Dave
Contributor

Hi Timothy,

I was under the impression that only the destination port had to match.

Thanks for your insight and info.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events