cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
975
Views
3
Helpful
2
Replies

CSA - Network Shield Rule Triggering for IGMP Packets

mnlatif
Level 3
Level 3

Hi,

Any ideas, why this Network Shield Rule (For Malicious Packet) is getting triggered for these IGMP Packets ?

TESTMODE: A packet with malicious content was detected. Reason: Malicious packet. IGMP: 10.1.2.136->224.0.0.22 type 0x22. The operation would have been denied.

TESTMODE: A packet with malicious content was detected. Reason: Malicious packet. IGMP: 10.1.2.144->224.0.0.1 type 0x11. The operation would have been denied.

As far I researched 0x11 (Query) and 0x22 (v3Report) are Valid IGMP Packets.

Thanks,

Naman

2 Replies 2

tsteger1
Level 8
Level 8

I think these are benign (I'm assuming this is a NAT'd adapter?) and are legit multicast traffic. Since the rule is set to deny and log, you are getting the messages.

If they weren't going to a multicast address (in this case igmp.mcast.net), you might get concerned.

Tom

Review Cisco Networking products for a $25 gift card