12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity377HSRP Invalid OpcodeBase Event:Details:<strong>Reference</strong>sHSRP_INVALID_OPCODEAn invalid opcode field was detected in an HSRP datagram. This violation of the standard couldindicate an attempt to compromise the protocol.HSRP SpecificationsHSRP Invalid StateBase Event:Details:<strong>Reference</strong>sHSRP_INVALID_STATEAn invalid state field was detected in an HSRP datagram. This violation of the standard couldindicate an attempt to compromise the protocol.HSRP SpecificationsHSRP Invalid TTL FieldBase Event:HSRP_BAD_TTLDetails: According to the RFC, datagrams carrying HSRP traffic have to have the Time-To-Live field set to 1in the IP header, though sometimes values of 2 may be seen during normal HSRP datagramexchange. Traffic was detected with a TTL value of greater than 2, which may indicate a spoofedpacket or a deliberate attempt to compromise the protocol.<strong>Reference</strong>sHSRP SpecificationsHSRP Invalid Version NumberBase Event:Details:<strong>Reference</strong>sHSRP_INVALID_VERNUMThe current HSRP version described by the most current RFC is version 0, but a different versionfield was seen. This violation of the standard could indicate an attempt to compromise the protocol.HSRP SpecificationsHSRP Nonauthenticated ConnectionBase Event:Details:<strong>Reference</strong>sHSRP_NONAUTH_CONNECTIONAn HSRP datagram with the default authentication field was seen. This is insecure and vulnerableto spoofing attacks. Routers participating in HSRP should be configured to use authenticated HSRPdatagram exchange.HSRP SpecificationsHSRP Resign From Nonactive RouterBase Event:Details:<strong>Reference</strong>sHSRP_NONACTIVE_RESIGNThe HSRP Resign message is used to indicate that an active router (router forwarding packets onbehalf of the virtual router) has ceded to a different router. However, a Resign message was receivedfrom a router which is not the currently active router. This violation of the standard could indicatean attempt to compromise the protocol.HSRP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!