cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
381
Views
0
Helpful
3
Replies

BO2K-UDP sig false positive

zachjansen
Level 1
Level 1

I'm experiencing what I believe to be a false positive on the BO2K-UDP (4055) signature. As near as I can tell, it is getting triggered by Xbox consoles when they connect to the Xbox Live! service. I am currently running the S307 sig update. What is the best way to report this to get it fixed?

Thanks,

Zach

3 Replies 3

jsivulka
Level 5
Level 5

Each signature has a section called Benign Trigger(s), you can use this to determine any false positives.In regards to IDS 5.0 modes refer to the following link:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dminter.htm

Other 5.0 documentation can be found at the link below:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/index.htm

cashqoo
Level 1
Level 1

I have encountered the BO2K alarm, after investigations, it is IPsec VPN traffic which triggers it.

you can tune the signature using IPS IDM.

If you have MARS, you have the option to create a false positive rule for it.

rgds

cash

mherald
Level 1
Level 1

I ran into this one too. After I looked at things, it is IPsec VPN traffic which triggered it. It was getting fired when traffic went to the outside interface of the PIX (not ASA). The PIX is also does remote user VPN traffic.

Mike

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: