Hi everyone,
We are currently running R81.20 Hotfix Take 105.
The IPS protection flagged a Sweep Scan originating from an internal server, with the destination showing as "null" and the service listed as HTTP_proxy (TCP/8080).
After 9 seconds, the system automatically applied a SAM rule to drop the connection. This action inadvertently disrupted legitimate communication with another internal server.
Once we identified the cause, we removed the affected server from the SAM rule, and since then the issue has not reappeared.
Could you help us understand what might be triggering this behavior?