Re: Tuning SIG 5583 - SMB Remote SAM Service Access Attempt
The filter says: os-relevance: not-relevant
But the alert says: os: idSource=learned type=windows-nt-2k-xp relevance=relevant
I suspect that is why this one filter is not matching.
You probally want to revert the os-relevance to its default setting for this filter.
Also, make sure you examine the 'stop-on-match' filters closely. If you match a filter that has 'stop-on-match true', it will stop evaluation of any more filters for that alert, so that could cause strange results.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...