fortigate me bloqueo mi proxy
Publicado: 16 Abr 2009, 17:06
Hola a todos soy nuevo en el uso del fortigate-a100 y estoy aprendiendo a usarlo el mismo ya esta en produccion mis firmas ips me detectaron un ataque adjunto los logs
essage meets Alert condition
The following intrusion was observed: "applications: MS.PowerPoint.Malformed.NamedShows.Record.Code.Execution".
date=2009-04-15 time=14:40:12 devname=FG100A3907511672 device_id=FG100A3907511672 log_id=0419070000 type=ips subtype=signature pri=alert vd=root fwver=040000 policyid=1 serial=10731 attack_id=13590 severity=critical carrier_ep=N/A profile=N/A sensor="protect_client" src=65.55.85.7 dst=192.168.97.21 src_port=80 dst_port=50424 src_int="wan1" dst_int="internal" status=detected proto=6 service=50424/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/VID13590" count=1 incident_serialno=1447711475 msg="applications: MS.PowerPoint.Malformed.NamedShows.Record.Code.Execution"
essage meets Alert condition
The following intrusion was observed: "tcp_reassembler: TCP.Stealth.Activity, paws out-of-range".
date=2009-04-15 time=14:55:38 devname=FG100A3907511672 device_id=FG100A3907511672 log_id=0419070000 type=ips subtype=signature pri=alert vd=root fwver=040000 policyid=1 serial=16909 attack_id=107937794 severity=low carrier_ep=N/A profile=N/A sensor="protect_client" src=70.38.40.114 dst=192.168.97.21 src_port=80 dst_port=54227 src_int="wan1" dst_int="internal" status=detected proto=6 service=54227/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/VID107937794" count=1 incident_serialno=1447711477 msg="tcp_reassembler: TCP.Stealth.Activity, paws out-of-range"
ssage meets Alert condition
The following intrusion was observed: "tcp_reassembler: TCP.Stealth.Activity, paws out-of-range".
date=2009-04-15 time=13:42:03 devname=FG100A3907511672 device_id=FG100A3907511672 log_id=0419070000 type=ips subtype=signature pri=alert vd=root fwver=040000 policyid=1 serial=319512 attack_id=107937794 severity=low carrier_ep=N/A profile=N/A sensor="protect_client" src=200.41.88.16 dst=192.168.97.21 src_port=80 dst_port=40955 src_int="wan1" dst_int="internal" status=detected proto=6 service=40955/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/VID107937794" count=1 incident_serialno=1117634675 msg="tcp_reassembler: TCP.Stealth.Activity, paws out-of-range"
y otro log donde el source es mi fuente y el destino ip publicas, basicamente ya he tomado las medidas revisando el log de mi proxy para ver las pc y tomar las medidas correctivas-
el problema que tengo ahora es que el fortigate me ha baneado mi proxy bloquenadole el acceso y en el browser me da este mensaje An attack was detected, originating from your system. Please contact the system administrator.
me gustaria me den una mano para quietar el banner de mi proxy y que recomendaciones me pueden dar acerca de los logs que estoy recibiendo.
Les quedo agredecidos por la atencion a mi inquietud.
Saludos
Fernando
essage meets Alert condition
The following intrusion was observed: "applications: MS.PowerPoint.Malformed.NamedShows.Record.Code.Execution".
date=2009-04-15 time=14:40:12 devname=FG100A3907511672 device_id=FG100A3907511672 log_id=0419070000 type=ips subtype=signature pri=alert vd=root fwver=040000 policyid=1 serial=10731 attack_id=13590 severity=critical carrier_ep=N/A profile=N/A sensor="protect_client" src=65.55.85.7 dst=192.168.97.21 src_port=80 dst_port=50424 src_int="wan1" dst_int="internal" status=detected proto=6 service=50424/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/VID13590" count=1 incident_serialno=1447711475 msg="applications: MS.PowerPoint.Malformed.NamedShows.Record.Code.Execution"
essage meets Alert condition
The following intrusion was observed: "tcp_reassembler: TCP.Stealth.Activity, paws out-of-range".
date=2009-04-15 time=14:55:38 devname=FG100A3907511672 device_id=FG100A3907511672 log_id=0419070000 type=ips subtype=signature pri=alert vd=root fwver=040000 policyid=1 serial=16909 attack_id=107937794 severity=low carrier_ep=N/A profile=N/A sensor="protect_client" src=70.38.40.114 dst=192.168.97.21 src_port=80 dst_port=54227 src_int="wan1" dst_int="internal" status=detected proto=6 service=54227/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/VID107937794" count=1 incident_serialno=1447711477 msg="tcp_reassembler: TCP.Stealth.Activity, paws out-of-range"
ssage meets Alert condition
The following intrusion was observed: "tcp_reassembler: TCP.Stealth.Activity, paws out-of-range".
date=2009-04-15 time=13:42:03 devname=FG100A3907511672 device_id=FG100A3907511672 log_id=0419070000 type=ips subtype=signature pri=alert vd=root fwver=040000 policyid=1 serial=319512 attack_id=107937794 severity=low carrier_ep=N/A profile=N/A sensor="protect_client" src=200.41.88.16 dst=192.168.97.21 src_port=80 dst_port=40955 src_int="wan1" dst_int="internal" status=detected proto=6 service=40955/tcp user=N/A group=N/A ref="http://www.fortinet.com/ids/VID107937794" count=1 incident_serialno=1117634675 msg="tcp_reassembler: TCP.Stealth.Activity, paws out-of-range"
y otro log donde el source es mi fuente y el destino ip publicas, basicamente ya he tomado las medidas revisando el log de mi proxy para ver las pc y tomar las medidas correctivas-
el problema que tengo ahora es que el fortigate me ha baneado mi proxy bloquenadole el acceso y en el browser me da este mensaje An attack was detected, originating from your system. Please contact the system administrator.
me gustaria me den una mano para quietar el banner de mi proxy y que recomendaciones me pueden dar acerca de los logs que estoy recibiendo.
Les quedo agredecidos por la atencion a mi inquietud.
Saludos
Fernando