IDP block VPN access
Hello, can anybody help me and explain best fix solution ?
After upgrade USG110 to FW4.65/or update IDP to 3.2.4.268, computer from our LAN
On router :
warn,idp,ACCESS BLOCK,lan1,wan1,tcp,Rule_id=20 SSI=N [type=Sig(1139379)] EXPLOIT PPTP Echo Request Buffer Overflow (CVE-2003-0213) Action: Reject Both Severity: high
https://threatintelligence.zyxel.com/idp
Ii this false detection ? Or is safe Disable this item from IDP ?
What i can do (create exception) ?
Thanks for help !
After upgrade USG110 to FW4.65/or update IDP to 3.2.4.268, computer from our LAN
cannot join to external VPN, using VPN from Windows 10 (before two weeks is connected OK).
warn,idp,ACCESS BLOCK,lan1,wan1,tcp,Rule_id=20 SSI=N [type=Sig(1139379)] EXPLOIT PPTP Echo Request Buffer Overflow (CVE-2003-0213) Action: Reject Both Severity: high
https://threatintelligence.zyxel.com/idp
Ii this false detection ? Or is safe Disable this item from IDP ?
What i can do (create exception) ?
Thanks for help !
0
Accepted Solution
-
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community
0
All Replies
-
Hi @kyssling
Could you provide the reproduced procedures to us?
Which VPN connection method you used on your Windows 10 PC? L2TP or SSL VPN?
BTW, if that would impact your VPN service, you could inactivate the IDP signature 1139379 temporarily.
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community
0 -
Hello, very thanks for fast answer, i try it on monday or wednesday (when user is on our Lan, from home he is connect to VPN without problem) and write feedback.
1 -
Hello, sorry for delay, but external worker have holiday ...
Today i try VPN connection and connect to external VPN is running without any problem.(She use PPTP protocol)So I search on IDP : [type=Sig(1139379)] EXPLOIT PPTP Echo Request Buffer Overflow (CVE-2003-0213) and NONE found...
Can you confirm that this signature is deleted on IDP update 3.2.4.269/3.2.4.270 ?
(on IDP to 3.2.4.268 this signature exist)
Thanks Vaclav
0 -
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight