Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG IPS rule dropping Windows 10 Upgrade assistant packets

Hi Guys,

I'm trying to update couple of windows 7 pro machines to Windows 10 using windows 10 upgrade assistance. However the traffic being dropped by IPS rule LAN--> WAN. Below is what I see in logs.

Time - 2017-05-09 09:53:01
Log Comp - Anomaly
Action - Drop
Source IP - 10.1.0.26 :TCP(53500)
Destination IP - 13.107.4.50 :TCP(80)
Signature ID - 1131031030
Signature Name - Malware Trojan-Downloader.Win32.Molelash.A Runtime Detection
Category - Malware Communication
Platform - Windows
Target - Client
Firewall Rule - 2
Message ID - 06002

 

Is there a way to add a custom IPS rule to allow traffic?

Thank you.



This thread was automatically locked due to age.
Parents Reply
  • Unfortunately yes, until snorts fixes the issue.

    Signature based IPS are subjected to false-positive...Open a ticket with Sophos Support in order to communicate the issue.

    In the meanwhile, if you need Windows 10 Upgrade Assistant allowed, create a temporary firewall rule that you enable as needed.

    Regards

Children