Hi - I have a simple setup for my 'home' network. Simple Masquerading for outbound traffic from clients, and a ANY ANY ANY packet filter rule. Only one inbound NAT fule which is to allow DNAT of incoming 443 SSL to go through Astaro and be directed to my Small Business Server 2003 running Exchange 2003 for pda syncing etc. This all works fine except when IPS is enabled.
In which case the following alert comes up on the live log and stops access to my IIS server dead in its tracks. The following log extract is (probably) my PDA, via T-Mobile GPRS, going through my router and then through Astaro.
2007:03:15-12:37:59 (none) barnyard[31539]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="WEB-MISC SSLv2 openssl get shared ciphers overflow attempt" group="211" srcip="149.254.200.222" dstip="192.168.168.180" proto="6" srcport="26216" dstport="443" sid="8428" class="Attempted Administrator Privilege Gain" priority="1" generator="1" msgid="0"
Only actions so far = 1. disable IPS, in which case all ok. 2. add a Manual rule modification for rule number 2101 (is this correct? ... I got it from the extract above) and disable this rule, but this does not seem to help.
Any clues anyone? Many thanks!
This thread was automatically locked due to age.