I get this 850 warning :
"Intrusion Protection Alert
An intrusion has been detected. The packet has *not* been dropped.
If you want to block packets like this one in the future, set the corresponding intrusion protection rule to "drop" in WebAdmin.
Be careful not to block legitimate traffic caused by false alerts though.
Details about the intrusion alert:
Message........: SMTP MAIL FROM overflow attempt
Details........: http://www.snort.org/pub-bin/sigs.cgi?sid=2590
Time...........: 2005:09:22-08:37:29
Packet dropped.: no
Priority.......: 1 (high)
Classification.: Attempted Administrator Privilege Gain IP protocol....: 6 (TCP)
Source IP address: 140.5.30.13"
The thing is it is coming from my mail server (Exchange ver5.5), Can I inform the Astaro that it is not intrusion or to ignore it in some way?
Alternatively, Can it be fixed by applying a patch on the Exchange server?
K
This thread was automatically locked due to age.