changes to sig 3010-0 with V6?

Unanswered Question
Jul 2nd, 2007

Can anyone tell me what changed with this sig in V6? Our old filter no longer work. It appears the normal source and destination IP addresses have been swapped but that particular setting on the sig has not changed AFAICT (it was and is set to swap-attacker-victim). The source is the Internet and high ports, the destination is our DMZ and port 443. So, I think this is reply traffic. Conceptually, why would you swap the source/destination for a high port sweep anyway?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)


This Discussion