Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS Inbound SIP Trying blocked

Default IPS rule has defined:

PROTOCOL-VOIP inbound 100 Trying message
20404
protocol-voip
1 - Critical
Windows, Linux, Unix...
Server
Drop packet

Thus the following is received:

2021-03-09 14:33:02IPSmessageid="07002" log_type="IDP" log_component="Signatures" log_subtype="Drop" ips_policy="" ips_policy_id="3" fw_rule_id="7" user="" sig_id="20404" message="PROTOCOL-VOIP inbound 100 Trying message" classification="Generic Protocol Command Decode" rule_priority="1" src_ip="192.168.100.104" src_country="R1" dst_ip="xxx" dst_country="DEU" protocol="TCP" src_port="52314" dst_port="5060" OS="BSD,Linux,Mac,Other,Solaris,Unix,Windows" category="protocol-voip" victim="Server"

Isnt this a pretty common traffic? Clients sends invite to ITSP Voip Server and it responds with Trying....



This thread was automatically locked due to age.
Parents Reply Children