Wondering if anybody has seen this before. We have a few apple machines that connect to our windows server for files and what not. Sometimes when they try to connect, IPS sees it as a attack, sig id = 2231 to be exact. Before I make it okay, I just want to verify if this is just a false positive or if anybody has ran into this before that can show me a direction to finding out if it is a threat or not.
Are you running HIPS 8.0 Patch 2 (build 8.0.0.2151) or higher? There was a fix for this in the Patch 2 build.
Yes, the server in question is running 8.0.2239. I don't mind if it is a false positive, I just want to make sure. If it is, I'll just add an exclusion for the 4-5 mac systems causing this issue into the IPS.
Message was edited by: awsomaha on 6/20/13 6:49:56 AM CDTDownload the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center
Corporate Headquarters
2821 Mission College Blvd.
Santa Clara, CA 95054 USA