2.17. IDP
These log messages refer to the IDP (Intrusion Detection & Prevention events) category.
2.17.1. scan_detected (ID: 01300001)
Default Severity
NOTICE
Log Message
Scan detected: <description>, Signature ID=<signatureid>. ID Rule:
<idrule>. Protocol: <ipproto>. Source IP: <srcip>. Source Port:
<srcport>. Destination IP: <destip>. Destination Port: <destport>.
Closing connection.
Explanation
A scan signature mapped to the "protect" action matched the traffic,
closing connection.
Gateway Action
close
Recommended Action
Research the advisory (searchable by the unique ID), if you suspect an
attack.
Revision
1
Parameters
description
signatureid
idrule
ipproto
srcip
srcport
destip
destport
Context Parameters
Rule Name
Deep Inspection
2.17.2. idp_notice (ID: 01300002)
Default Severity
WARNING
Log Message
IDP Notice: <description>, Signature ID=<signatureid>. ID Rule:
<idrule>. Protocol: <ipproto>. Source IP: <srcip>. Source Port:
<srcport>. Destination IP: <destip>. Destination Port: <destport>.
Closing connection.
Explanation
A notice signature mapped to the "protect" action matched the traffic,
closing connection.
Gateway Action
close
Recommended Action
This is probably not an attack, but you may research the advisory
(searchable by the unique ID).
Revision
1
Parameters
description
signatureid
idrule
ipproto
srcip
2.17. IDP
Chapter 2. Log Message Reference
225
Summary of Contents for DFL-210 - NetDefend - Security Appliance
Page 25: ...List of Tables 1 Abbreviations 28 25...
Page 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26...
Page 36: ...1 3 Severity levels Chapter 1 Introduction 36...
Page 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195...
Page 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409...
Page 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476...