cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
289
Views
0
Helpful
2
Replies

Nachi detected from 3015 Concentrator?

jason.scott
Level 1
Level 1

Our IDS shows each day about 20 nachi alarms orginating from the private ip address of our 3015 vpn concentrator and I'm at a loss to explain it.

This occurs regardless of clients being connected or not. ICMPs are filtered and dropped both in and outgoing on the box.

The IDS signature shows the nachi alarms as coming from and to port 0, which also seems strange.

Does anyone know what could be causing this?

Btw we are running 3.x of IDS - have yet to upgrade to 4.x

2 Replies 2

umedryk
Level 5
Level 5

This is basically due to the limitations of 3.1 code. 4.0 should not have any such problems.

mcerha
Level 3
Level 3

Could you please send a traffic sample directly to me at mcerha@cisco.com. I will look into the exact cause.