IPS iSCSI warnings.

jef
jef Posts: 80  Ally Member
First Comment Second Anniversary
edited June 22 in USG FLEX H Series

What is this warning telling me?
I am familiar with both the source and the destination machines.

Is this reporting that the source "192.168.11.13" is doing something to the destination that is harmful or unwanted?

I am very familiar with the source, and I would like to assume it is clean an safe.
What is IPS detecting exactly?

IPS-iSCSC.png

the above has over 900 warnings stacked. So, I don't want to dismiss it, I'd like to understand it. When i google the iSCSI / iSNS it doesn't help me understand my scenario.

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,296  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @jef ,

    To look up information about any IPS Signature ID, please refer to this link, enter the Signature ID, and click Search.

    https://threatintelligence.zyxel.com/idp

    Zyxel_Judy

  • jef
    jef Posts: 80  Ally Member
    First Comment Second Anniversary

    I had already done that, if you click in application, on the signature it opens the signature explaination.
    But, it doesn't tell you what you need to know as an Admin, it explains why it is a signature IPS issue.

    I scanned the source IP box and it returned clean, multiple times.
    So I am confused at what the IPS alarm is all about and what triggered it.

    What triggered it. If the source is known, and the source doesn't have any malware.
    Why is the error being thrown.

  • jef
    jef Posts: 80  Ally Member
    First Comment Second Anniversary

    This tells me to? Yes the source IP server is Linux and the Destination is AWS linux.

    Why does IPS think the source is attacking the destination??

    Screenshot from 2025-06-23 16-31-35.png