Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ISA570 Question

Hi there

I am operating an ISA570 and I get the IPS alerts bellow. Any idea what this could be? Somthing to worry about?

This is an automatic message sent by ISA570 (Name: WEB12AB).

---------------------------

Action-Rule Name-Rule ID-Source IP-Source Port(type)-Destination IP-Destination Port(code)-Protocol-Hit Count


Block and Log-SHELLCODE Egg Hunter -1-1055107-37.59.232.98-54753-192.168.70.11-443-TCP-1

Block and Log-SHELLCODE Egg Hunter -1-1055107-37.59.232.98-54758-192.168.70.12-443-TCP-1

Behind the ISA570 I have 2 identical servers running several VMs. All Debian based and all 100% manually setup by myself.

Thanks & cheers,

Peter

120
Views
0
Helpful
0
Replies
CreatePlease to create content