{"id":11136,"date":"2020-09-04T11:24:22","date_gmt":"2020-09-04T09:24:22","guid":{"rendered":"https:\/\/www.boc.de\/watchguard-info-portal\/?p=11136"},"modified":"2020-09-18T12:59:35","modified_gmt":"2020-09-18T10:59:35","slug":"swyxit-ips-false-positive","status":"publish","type":"post","link":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2020\/09\/swyxit-ips-false-positive\/","title":{"rendered":"Swyxit! IPS false positive"},"content":{"rendered":"<h6>Setup:<\/h6>\n<p>SwyxIt!-Softphone greift auf Swyx-TK-Anlage via BOVPN-Tunnel zu.<\/p>\n<h6>Symptom:<\/h6>\n<p>Swyxit Softphone Client zeigt keinen Status nach Login.<\/p>\n<h6>Beobachtung:<\/h6>\n<p>auf der Firewall sind folgende Log-Eintr\u00e4ge zu sehen:<\/p>\n<div id=\"post-list\">\n<div class=\"post-list-holder-by-time\">\n<div class=\"post-list__table\">\n<div id=\"postListContent\" class=\"post-list__content\">\n<div id=\"post_8dgfc6ytntf67cg7ef4yjjf5ch\" class=\"post other--root current--user\">\n<div class=\"post__content \">\n<div id=\"8dgfc6ytntf67cg7ef4yjjf5ch_message\" class=\"post__body \">\n<div class=\"post-message post-message--collapsed\">\n<div class=\"post-message__text-container\">\n<div class=\"post-message__text\">\n<pre>2020-09-07 10<span data-emoticon=\"14\">:14:<\/span>43 Deny 10.xxx.xxx.xxx 10.xxx.yyy.zzz sip\/udp 5070 5060 [...] <strong>IPS detected<\/strong> [...] proc_id=\"firewall\" rc=\"301\" msg_id=\"3000-0150\" \r\nsrc_ip_nat=\"10.xxx.xxx.xxx\" <strong>signature_name=\"SIP Digium Asterisk SIP CSeq Heap Buffer Overflow (CVE-2017-937\" \r\n<\/strong><strong>signature_cat=\"Buffer Over Flow\" signature_id=\"1133858\" severity=\"4\"<\/strong> [...]<\/pre>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div id=\"post-create\" class=\"post-create__container\">\n<form id=\"create_post\" class=\"\" role=\"form\">\n<div class=\"post-create\">\n<div class=\"post-create-body\">\n<div class=\"post-body__cell\">\n<div class=\"textarea-wrapper\">\n<div>\n<p>Scheinbar triggert der Swyx-Client hier beim Verbindungsaufbau zur Swyx-TK-Anlage gelegentlich das IPS.<\/p>\n<\/div>\n<h6>Abhilfe:<\/h6>\n<\/div>\n<\/div>\n<\/div>\n<ul>\n<li data-wp-editing=\"1\">Policy-Manager<br \/>\n=&gt; Subscription-Services<br \/>\n=&gt; [Exceptions]\n=&gt; Entsprechende ID einf\u00fcgen =&gt; ADD =&gt; OK =&gt; OK<br \/>\n=&gt; Policy auf Firewall schreiben.<a href=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h52_40.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-11137 size-medium\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h52_40-262x300.png\" alt=\"\" width=\"262\" height=\"300\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h52_40-262x300.png 262w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h52_40.png 515w\" sizes=\"(max-width: 262px) 100vw, 262px\" \/><\/a><\/li>\n<\/ul>\n<\/div>\n<p><a style=\"font-size: inherit; background-color: #ffffff;\" href=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h57_01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-11138 size-medium\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h57_01-300x279.png\" alt=\"\" width=\"300\" height=\"279\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h57_01-300x279.png 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2020\/09\/2020-09-07_10h57_01.png 524w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<\/form>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Setup: SwyxIt!-Softphone greift auf Swyx-TK-Anlage via BOVPN-Tunnel zu. Symptom: Swyxit Softphone Client zeigt keinen Status nach Login. Beobachtung: auf der Firewall sind folgende Log-Eintr\u00e4ge zu sehen: 2020-09-07 10:14:43 Deny 10.xxx.xxx.xxx 10.xxx.yyy.zzz sip\/udp 5070 5060 [&#8230;] IPS detected [&#8230;] proc_id=&#8221;firewall&#8221; rc=&#8221;301&#8243; msg_id=&#8221;3000-0150&#8243; src_ip_nat=&#8221;10.xxx.xxx.xxx&#8221; signature_name=&#8221;SIP Digium Asterisk SIP CSeq Heap Buffer Overflow (CVE-2017-937&#8243; signature_cat=&#8221;Buffer Over Flow&#8221; signature_id=&#8221;1133858&#8243; severity=&#8221;4&#8243; [&#8230;] Scheinbar triggert der Swyx-Client hier beim Verbindungsaufbau zur &hellip; <a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2020\/09\/swyxit-ips-false-positive\/\" class=\"more-link\">Weiterlesen <span class=\"screen-reader-text\">Swyxit! IPS false positive<\/span> <span class=\"meta-nav\">&raquo;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[400,683],"class_list":["post-11136","post","type-post","status-publish","format-standard","hentry","category-watchguard-technischer-blog","tag-ips","tag-swyx"],"_links":{"self":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/11136"}],"collection":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/comments?post=11136"}],"version-history":[{"count":4,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/11136\/revisions"}],"predecessor-version":[{"id":11142,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/11136\/revisions\/11142"}],"wp:attachment":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/media?parent=11136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/categories?post=11136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/tags?post=11136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}