The subject should say it all.
Long story short - I was having issues with my ASG box so I decided, after many attempts to fix the problem, to rebuild the box from scratch.
That went fine and all that was not working now is working again; with the exception of IPS. That is working worse!
ASG version 6.304 by the way.
Every half hour I am getting multiple emails about anomaly detections (about one hundred events being reported each half hour).
No matter what I have tried I cannot stop these emails from spamming me.
The subject of the emails are:
[WARN-854] Anomaly Intrusion Protection Alert and
[WARN-855] Anomaly Intrusion Protection Alert - Event buffering activated
The data is:
2007:04:09-04:49:36 Anomaly A Non-live dest used: local dest, udp: 1.0000 UDP .1:32775 -> 203.10.1.9:53
2007:04:09-04:49:36 Anomaly A Non-live dest used: local dest, udp: 1.0000 UDP .1:32775 -> 203.21.20.20:53
I have searched the forums – found some info on this but all that was suggested is that DNS servers be defined so that Root DNS servers are not used.
This is what I have done so far:
Proxies > DNS
Interfaces to listen on: Internal
Allowed Networks: Internal (Network)
Forwarding Name Servers > 203.10.1.9 & 203.21.20.20
( by the way – these are the addresses that are being reported as the anomaly event! )
Intrusion Protection > Settings
Global Settings > Local Networks > Internal (Network)
Anomaly Detection > Enabled
Notification Levels > Disabled (initially just disabled Notify on Anomaly Events but this had no affect)
Intrusion Protection > Advanced
IPS Network Exclusions
External (Address) -> DNS Server (primary)
External (Address) -> DNS Server (secondary)
The primary and secondary definitions are defined in Networks as the above DNS Server IP addresses.
Although I was experiencing issues prior to the rebuild, IPS was not one of them and I had the same DNS Server settings defined and anomaly detection was turned on.
Nothing that I do stops the emails. This is driving me nuts.
Someone please tell me what I can do to resolve this issue.
This thread was automatically locked due to age.