- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-08-2019 05:32 PM
is it just me or anyone seeing SIPVicious Scanner Detection alerts a lot recently?
08-09-2019 12:52 PM
Hello,
Join the club. I have seen them for over 7 years now. I created a special modified policy to drop the traffic. Yes it common and so are a bunch of others such as shodan, etc.
Regards,
08-09-2019 12:52 PM
Hello,
Join the club. I have seen them for over 7 years now. I created a special modified policy to drop the traffic. Yes it common and so are a bunch of others such as shodan, etc.
Regards,
10-14-2019 06:37 AM
@OtakarKlier can you please let me know the policy details. I'll try to create it on my end. these are creating a lot of noise on my firewalls.
10-29-2019 07:03 PM
Same problem! Could you please share with me the policy details?
10-30-2019 05:26 PM
@OtakarKlier Same problem! Could you please share with me the policy details?
11-04-2020 06:17 AM
Any chance I could get the details on the rule you created or is it posted somewhere?
11-04-2020 02:40 PM
Hello,
In your Vulnerability profile, set it to block anything medium and higher. SipVicious used to be low but since I block anything medium and higher, a custom policy is not longer required for me. But you can still block/unblock is with an exception.
Just change the action to like drop.
Regards,
11-22-2022 10:40 AM
I am a new user of a Palo Alto firewall. Where would I set up this policy? we are running version 9.1.12. Sorry, just a newbie here. I have tried finding it and am having problems.
Thank you,
Bridget
11-22-2022 12:40 PM
Hello,
Welcome. Here is how you would perform this.
Click on 'Objects' at the top
Then 'Vulnerability Protection' on the left.
Click on the name of the policy you wish to add the exclusion to (you cannot change the strict or default policies that are there by default, you will need to 'Clone' (at the bottom) one and edit that.
Once the profile is opened, click 'Exceptions tab.
At the bottom click 'Show All Signatures', in the search/filter bar type SIPVicious
This will display the policy that is alerting.
Click the 'Enable' checkbox on the left.
Click OK
Click 'Commit' in the upper right to send the changes to the configuration (running and start)
Hope this helps.
11-22-2022 01:02 PM
So first I have to set up a policy to check for these alerts?
11-22-2022 01:16 PM
Hello,
That is correct. The Security Policy is the one that actually does the enforcement on the configuration set on it. Say you have a security policy and no profiles set, then this policy will not be looking for such things as the SIPVicious scanner, etc. I would recommend setting up your Security Profiles first then add those to the Security Policies.
Hope that makes sense.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!