Hi,
I have problems with IPS in UTM, the UTM handles IPSEC traffic with VEEAM backup and Replication, and triggers this:
This thread was automatically locked due to age.
Hi,
I have problems with IPS in UTM, the UTM handles IPSEC traffic with VEEAM backup and Replication, and triggers this:
ThorstenSult said:What happens if you create a second exception list for the other subnet (to destination)?
-----
Best regards
Martin
Sophos XGS 2100 @ Home | Sophos v19 Architect
Hi Karl-heinz,
Thanks for pointing out ;-)
Only thing is, that if another host/server behind the UTM, get's the SAMSAM attack, then it would just ignore it, therefore I hoped for the host exception to work, but there is a problem with UTM in that matter I see.
Tried to change from IPSEC to RED Site-2-site, just for fun, but of course, the issue remains :-)
-----
Best regards
Martin
Sophos XGS 2100 @ Home | Sophos v19 Architect
Hello Martin,
Just a silly thought... does VEEAM backup keep connections open all the time or does it start new connections everytime? IPS exceptions are applied to new connections, not existing ones.
If not sure, I think you can force it by disabling one of the interfaces, then re-enable.
Regards,
Karl-Heinz
Hi,
Sorry the delay :-)
No unfortunately it's still the same. I rebooted veeam server also, with no effect, only thing that do work it the "advanced" pane and change the way it should report.
I will commit to support ticket :-)
-----
Best regards
Martin
Sophos XGS 2100 @ Home | Sophos v19 Architect
Hi Hermann0,
Yes, support tried a lot, but finally found out, that when making IPS exceptions, I could not choose the service,but only the device, and to be sure with my traffic, we had to add them as here:
It did not look that it was something they would fix, as this works as designed, I was told :-)
I just needed to know it first:-)
-----
Best regards
Martin
Sophos XGS 2100 @ Home | Sophos v19 Architect