The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About Brandon123s
Brandon123s

Brandon123s

Conversationalist

Member since Aug 10, 2022

‎08-10-2022
Kudos from
User Count
martin-netx
martin-netx
1
billyzoellers
billyzoellers
1
Rhodri
Rhodri
2
SteveBradbury
SteveBradbury
1
41D5
41D5
3
View All
Kudos given to
User Count
haupt
Meraki Employee haupt
1
BrianMorris
BrianMorris
1
41D5
41D5
1
View All

Community Record

5
Posts
12
Kudos
0
Solutions

Badges

First 5 Posts
First 10 Kudos
Lift-Off View All
Latest Contributions by Brandon123s
  • Topics Brandon123s has Participated In
  • Latest Contributions by Brandon123s

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Brandon123s in Security / SD-WAN
‎08-10-2022 08:19 AM
6 Kudos
‎08-10-2022 08:19 AM
6 Kudos
I don't agree with the resolution of this issue from Meraki.    Can you confirm that a 100% patched environment does not suffer from the false positive detections? A few people in this thread seem to have stated the false positive detections are still happening despite patching.   As I understand it the only way to be protected from this not yet seen in the wild exploit and still have TLS 1.2 working is to whitelist this rule and patch systems.   edit: I believe this is now resolved as the affected SNORT rule has been adjusted. At least one post here says this has resolved the issue after re-enabling the rule. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Brandon123s in Security / SD-WAN
‎08-10-2022 08:10 AM
1 Kudo
‎08-10-2022 08:10 AM
1 Kudo
the CVE itself says there is no known exploits for this in the wild. The CVE is from yesterday and it's all about TLS 1.2 hellos. Anything using TLS 1.2 could be affected here. Tons of companies use amazon AWS, so the above whois probably some vendor hosted service that people authenticate against. I also have clients in my network connecting to similar aws compute resources and reporting the same thing. The traffic being blocked though is initiated by clients within my LAN, not from the outside. In your security center events log, are you seeing incoming traffic being blocked from that address?   ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Brandon123s in Security / SD-WAN
‎08-10-2022 07:54 AM
1 Kudo
‎08-10-2022 07:54 AM
1 Kudo
This is because the exploit mitigation rule targets too frequent TLS 1.2 hellos. Anything using TLS 1.2 could be blocked and some non-microsoft services were at my org according to the logs. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Brandon123s in Security / SD-WAN
‎08-10-2022 07:53 AM
4 Kudos
‎08-10-2022 07:53 AM
4 Kudos
The KB patch will not fix this, as the patch only prevents the exploit from working.   Blocking of legitimate traffic is simply a false positive. Until they update the rule it will always block legitimate TLS 1.2 handshakes that happen too frequently in accordance to how the rule is implemented.   Patch + whitelist is the only method that will work and keep us protected until meraki fixes the rule. ... View more

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

by Brandon123s in Security / SD-WAN
‎08-10-2022 07:51 AM
‎08-10-2022 07:51 AM
Upon applying the rule it took a few minutes for it to take effect for my org. Within 5 minutes the whitelist was recognized and there were no more issues.   You get this working? ... View more
Kudos from
User Count
martin-netx
martin-netx
1
billyzoellers
billyzoellers
1
Rhodri
Rhodri
2
SteveBradbury
SteveBradbury
1
41D5
41D5
3
View All
Kudos given to
User Count
haupt
Meraki Employee haupt
1
BrianMorris
BrianMorris
1
41D5
41D5
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
6 20321

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
4 20863

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
1 20487

Re: IPS Snort Microsoft Windows IIS denial-of-service attempt - False posit...

Security / SD-WAN
1 20827
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Cookies
  • Terms of Use
© 2023 Meraki