    Apple machine creating intrustion event


      Wondering if anybody has seen this before.  We have a few apple machines that connect to our windows server for files and what not.  Sometimes when they try to connect, IPS sees it as a attack, sig id = 2231 to be exact.  Before I make it okay, I just want to verify if this is just a false positive or if anybody has ran into this before that can show me a direction to finding out if it is a threat or not.