Threat name in NSM SaaS/NSM On-Prem/Analytics

Description

At times, the firewall will drop certain packets marked as “threat name” that do not have defined threat names associated with them. This is expected and the name will get an assigned number such as “Virus-60363”.

Cause

There may be a discrepancy between what is seen in Analytics and in the firewall as one may show as a randomly assigned number such as “Virus-60363”  in a report within your analytics server and on the firewall it may just show differently for GAV ID.

 

Resolution

This is due to our Cloud GAV service blocking that packet. With there being millions of signatures, we do not have names mapped for all of them. It will only show as ID only.

This behavior is to be expected.

Image

Related Articles

  • Ports used by NSM On-Prem
    Read More
  • Enable reporting for any firewall managed by NSM On-Prem 3.0 or above
    Read More
  • NSM On-Prem: How to collect System Logs
    Read More
not finding your answers?