TheAmboyduke
Technical User
We have an XTM 5 Series firebox running WSM 11.3.2. We have had it for awhile but the boss had never used the Intrusion prevention on it. He turned it on a couple of weeks ago. We have been adding stuff to the HTTP exceptions as needed. We are IT for a county. I will admit my firewall exp. is not the greatest. The adult probabtion department has a website that they import scanned documents to. Ever since we have turned n Intrusion prevention they have been having issues. Sometime the scans will go successfully sometimes they wont. They are not getting any firewall message when they fail. We added the website to the http exceptions, we added a rule in the FTP upload/download for .pdf. We were getting a message on Traffic monitor saying "tcp syn checking failed". We turned this off but their problems continue. Now the only message that comes across the Traffic Monitor is: "2013-04-04 10:53:16 Deny 50.58.28.232 24.117.89.66 64745/tcp 443 64745 0-External Firebox Denied 40 57 (Unhandled External Packet-00) proc_id="firewall" rc="101" tcp_info="offset 5 A 343323016 win 32950" Traffic"
I asked the boss to turn of the intrusion prevention to see if scanning issues went away and they did. As soon as we turned it back on the issues came back. I find it very puzzling that it doesnt happen all the time, but is happening on a very regular basis.
Any help in this matter would be greatly appreciated.
I asked the boss to turn of the intrusion prevention to see if scanning issues went away and they did. As soon as we turned it back on the issues came back. I find it very puzzling that it doesnt happen all the time, but is happening on a very regular basis.
Any help in this matter would be greatly appreciated.