CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
I'm seeing the same behavior post-upgrade to 6.203. This config has been working since we first built this firewall...I doubt we had it "wrong" all this time.
Globally disabling IPS from the Settings tab worked for me too - I couldn't get the other things I attempted within IPS (network exclusions, etc) to have any impact.
es gibt einen Workaround, der allerdings noch nicht offiziell getestet ist:
Fügen Sie in die Datei snort.conf-default folgende Zeilen hinzu:
config disable_decode_drops
config disable_tcpopt_experimental_drops
config disable_tcpopt_obsolete_drops
config disable_ttcp_drops
config disable_tcpopt_drops
config disable_ipopt_drops
config disable_decode_alerts
Danach den Snort neu starten und das Problem sollte behoben sein. Im nächsten Update wird sich hier ausserdem noch was tun.
[SIZE=2]I had a similar case:
After upgrading to 6.203 the SpamRelease that was configured working from outside and inside (mail.customer.com, port xxxx) worked only from outside.
The solution was that IPSPOOFING had to be changed from strict to normal. You find that configuration in Packet Filter >> Advanced
Maybe there were changes in the definition how IPSPOOFING works...
[/SIZE]