[7.450][BUG][FIXED] IPS blocked MS RDP over VPN Net-2-Net

It is not possible an unencrypted RDP connection via a VPN tunnel to build.
Linux RDP Client, RDP Server MS XP Pro SP3

id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="MISC MS Terminal Server no encryption session initiation attempt" group="110" srcip="192.168.100.11" dstip="192.168.200.2" proto="6" srcport="55196" dstport="3389" sid="2418" class="Attempted Denial of Service" priority="2" generator="1" msgid="0" 


MfG E. Riedel
Parents Reply
  • Just disable the errant rule in the advanced tab under the IPS settings; IPS systems require a bit of tuning sometimes; this is not the first time I've seen this rule triggered falsely by legitimate RDP traffic (and that rule dates back to Version 6).  I would not consider this a "bug."

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children