SMB Fragment Packet Found(32332)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SMB Fragment Packet Found(32332)

L4 Transporter

Hi,

Anyone have experience of this firing off continuously for 'normal' LAN traffic (deffo not being used as an evasion technique) since the signature was modified (v337)?

Cheers

1 REPLY 1

L6 Presenter

It is set for medium severity (https://threatvault.paloaltonetworks.com/Home/ThreatDetail/32332) which would mean that it will be blocked if you use a somewhat sane IPS setup of:

critical: block

high: block

medium: block

low: default

informational: default

What about if you block the traffic in your case - will the clients start to complain? Any specific clients like Win8 or Samba *nix clients or such (to narrow it down)?

  • 1644 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!