Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Thousands of intrusion attacks reported

We are seeing thousands of alerts from our Sophos Firewall Manager and from the local Sophos XG firewalls and most of them are either "Apache HTTP Server mod_rewrite RewriteLog Command Execution dangerous" or "Autodesk Design Review GIF GlobalColorTable DataSubBlock Buffer Overflow".

I have re-enabled IPS for my main firewall policy for user outbound Internet browsing (was told by support at one time to disable that, then found a post that said to enable it...???).

I also enabled some setting under the DoS settings too...

I need to know if these attacks are getting through and doing any real damage or is the firewall just reporting what it sees and I am protected?

I have a feeling the Autodesk alert is related to the fact that we have hundreds of Autodesk application users internally and this is just some false positive that the firewall is not sure what to do with, but that is a concern too.

Mainly looking for advice on how to best interpret these alerts.



This thread was automatically locked due to age.
Parents Reply Children
No Data