<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter 7120 false positives with Windows TCP keepalives in Security e-Series</title>
    <link>https://community.hpe.com/t5/security-e-series/filter-7120-false-positives-with-windows-tcp-keepalives/m-p/4826871#M121</link>
    <description>&lt;P&gt;Yes, filter 7120 isn't very good.&amp;nbsp; They tried to fix it again in June ( &lt;A target="_blank" href="http://threatlinq.tippingpoint.com/blog/?p=2095"&gt;http://threatlinq.tippingpoint.com/blog/?p=2095&lt;/A&gt;﻿ ) but it didn't help.&amp;nbsp; Just disable it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2011 18:17:01 GMT</pubDate>
    <dc:creator>Dan Nelson_6</dc:creator>
    <dc:date>2011-07-14T18:17:01Z</dc:date>
    <item>
      <title>Filter 7120 false positives with Windows TCP keepalives</title>
      <link>https://community.hpe.com/t5/security-e-series/filter-7120-false-positives-with-windows-tcp-keepalives/m-p/2367927#M113</link>
      <description>&lt;P&gt;Have a question about the following filter, which we're seeing a lot of false positives on:&lt;/P&gt;&lt;P&gt;7120: TCP: Segment Overlap With Different Data, e.g., Fragroute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The description for the filter says that it does not include the one garbage octet for TCP keepalives, but it appears that it is indeed firing for Windows TCP keepalive messages. &amp;nbsp;Packet traces I've taken show that the sequence number of the keep-alive packet is one less than the current sequence number, with 0x00 as the payload. &amp;nbsp;Yet filter 7120 still fires for that packet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this confirmed to be a problem? &amp;nbsp;Will most likely disable this rule, but wanted to see if there was a fix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2011 16:55:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/filter-7120-false-positives-with-windows-tcp-keepalives/m-p/2367927#M113</guid>
      <dc:creator>recallscottwalk</dc:creator>
      <dc:date>2011-03-31T16:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Filter 7120 false positives with Windows TCP keepalives</title>
      <link>https://community.hpe.com/t5/security-e-series/filter-7120-false-positives-with-windows-tcp-keepalives/m-p/4826871#M121</link>
      <description>&lt;P&gt;Yes, filter 7120 isn't very good.&amp;nbsp; They tried to fix it again in June ( &lt;A target="_blank" href="http://threatlinq.tippingpoint.com/blog/?p=2095"&gt;http://threatlinq.tippingpoint.com/blog/?p=2095&lt;/A&gt;﻿ ) but it didn't help.&amp;nbsp; Just disable it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2011 18:17:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/filter-7120-false-positives-with-windows-tcp-keepalives/m-p/4826871#M121</guid>
      <dc:creator>Dan Nelson_6</dc:creator>
      <dc:date>2011-07-14T18:17:01Z</dc:date>
    </item>
  </channel>
</rss>

