The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About Rhodri
Rhodri

Rhodri

New here

Member since Aug 10, 2022

‎08-10-2022
Kudos from
User Count
41D5
41D5
3
SteveBradbury
SteveBradbury
1
Eclipse
Eclipse
1
nlev
nlev
1
BrianMorris
BrianMorris
1
View All
Kudos given to
User Count
41D5
41D5
1
Brandon123s
Brandon123s
2
AxPayne
AxPayne
1
EricI
EricI
1
TechNick92
TechNick92
1
View All

Community Record

13
Posts
7
Kudos
0
Solutions

Badges

First 5 Posts View All
Latest Contributions by Rhodri
  • Topics Rhodri has Participated In
  • Latest Contributions by Rhodri

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 10:40 AM
‎08-10-2022 10:40 AM
Not sure if it helps but ours is set like this and it works.     ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 09:31 AM
‎08-10-2022 09:31 AM
What device do you have?   ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 08:35 AM
‎08-10-2022 08:35 AM
Yeah, it says "null" after you apply it but it does work. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 08:27 AM
1 Kudo
‎08-10-2022 08:27 AM
1 Kudo
You are correct. Patching does not prevent false positives and the blocking of traffic. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 08:25 AM
2 Kudos
‎08-10-2022 08:25 AM
2 Kudos
This isn't a solution. Patching endpoints does not prevent the offending traffic and it doesn't prevent it from being blocked.   You cannot currently fix the problem without either disabling IDS or by creating a rule. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 08:20 AM
3 Kudos
‎08-10-2022 08:20 AM
3 Kudos
The patch only applies to servers. It won't prevent Meraki traffic being blocked from "endpoints that are leveraging TLS 1.2", as Microsoft put it.   I think we need to wait for Microsoft to close out the incident - MO411804. They're "engaging with their firewall partners" so presumably the snork rule will be corrected at some point. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 06:50 AM
1 Kudo
‎08-10-2022 06:50 AM
1 Kudo
Is there a patch for Windows 10? The Microsoft CVE only refers to Windows Server operating systems. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 06:37 AM
‎08-10-2022 06:37 AM
Hi. Here you go...   https://community.meraki.com/t5/Security-SD-WAN/IPS-Snort-Microsoft-Windows-IIS-denial-of-service-attempt-False/m-p/156658/highlight/true#M39336 ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 06:33 AM
‎08-10-2022 06:33 AM
If you have an MX100 then go to "Security & SD WAN" then "threat protection". Under "Intrusion detection and prevention", add a rule and search for "1:60381". Save changes.   You should read the Microsoft CVE and snort rule before doing this, so you can determine whether your environment is actually vulnerable to this exploit.   https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2022-35748 https://snort.org/rule_docs/1-60381 ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 06:30 AM
‎08-10-2022 06:30 AM
We've added an allow rule on our MX100s for this particular type of traffic. It's on the list of rules as "1:60381". This has resolved the problem. We need more information from Microsoft on the potential ongoing threat/mitigation. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 04:54 AM
‎08-10-2022 04:54 AM
How do you know it's a false-positive? ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 04:46 AM
‎08-10-2022 04:46 AM
Haven't tried that but we're seeing thousands of dropped events on our MX100s, which could potentially indicate some kind of attack. So we don't want to disable any security related features. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Rhodri in Security / SD-WAN
‎08-10-2022 04:32 AM
‎08-10-2022 04:32 AM
We have the same issue. It's affecting all VPN and on-site users. I've logged a ticket with Meraki but haven't had a response yet. ... View more
Kudos from
User Count
41D5
41D5
3
SteveBradbury
SteveBradbury
1
Eclipse
Eclipse
1
nlev
nlev
1
BrianMorris
BrianMorris
1
View All
Kudos given to
User Count
41D5
41D5
1
Brandon123s
Brandon123s
2
AxPayne
AxPayne
1
EricI
EricI
1
TechNick92
TechNick92
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
3 16471

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
2 16363

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
1 16310

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
1 18134
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Cookies
  • Terms of Use
© 2023 Meraki