Video Screencast Help

[SID: 55000] IRC Identification Signature attack detected but not blocked.

Created: 04 Apr 2014 | 1 comment

For some reason when I receive the IPS alert as seen below, it's not blocking the traffic. I searched and found an identical posted article but it contained so solution. After opening IPS policy, I opened the Exceptions to see what rule 55000 was set for by default. It shows it as Block and Log. So why is the logged alert showing it as detect only?

Version: 12.1.2015.2015

[SID: 55000] IRC Identification Signature attack detected but not blocked. Application path: \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASHPLAYERPLUGIN_12_0_0_77.EXE

Operating Systems:

Comments 1 CommentJump to latest comment

Brɨan's picture

See here:

http://www.symantec.com/docs/TECH161411

It's more of just a method to alert you of this traffic, it's up to you to decide whether or not to block it.

Did you actually add as an exception to block?

https://www-secure.symantec.com/connect/articles/h...

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.