X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;ds=sidebyside;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fms_ipsec_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fms_ipsec_rules.xml;h=07f43001ecbe63977e8ac069cc6ed66ea0eab98b;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hp=0000000000000000000000000000000000000000;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b;p=ossec-hids.git diff --git a/debian/ossec-hids/var/ossec/rules/ms_ipsec_rules.xml b/debian/ossec-hids/var/ossec/rules/ms_ipsec_rules.xml new file mode 100644 index 0000000..07f4300 --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/ms_ipsec_rules.xml @@ -0,0 +1,149 @@ + + + + + + + 18104 + ^4646$ + IKE DoS-prevention mode started + windows, + + + + + 18105 + ^4652$|^4653$ + An IPsec Main Mode negotiation failed + windows, + + + + + 18105 + ^4654$ + An IPsec Quick Mode negotiation failed + windows, + + + + + 18104 + ^4983$|^4984$ + An IPsec Extended Mode negotiation failed + windows, + + + + + 18104 + ^4960$ + IPsec dropped an inbound packet that failed an integrity check + windows, + + + + + 18104 + ^4961$|^4962$ + IPsec dropped an inbound packet that failed a replay check + windows, + + + + + 18104 + ^4963$ + IPsec dropped an inbound clear text packet that should have been secured + windows, + + + + + 18104 + ^4965$ + IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI) + windows, + + + + + 18104 + ^4976$ + During Main Mode negotiation, IPsec received an invalid negotiation packet + windows, + + + + + 18104 + ^4977$ + During Quick Mode negotiation, IPsec received an invalid negotiation packet + windows, + + + + + 18104 + ^4978$ + During Extended Mode negotiation, IPsec received an invalid negotiation packet + windows, + + + + + 18104 + ^5453$ + An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started + windows, + + + + + 18105 + ^5480$ + IPsec Services failed to get the complete list of network interfaces on the computer + windows, + + + + + 18105 + ^5483$ + IPsec Services failed to initialize RPC server. IPsec Services could not be started + windows, + + + + + 18105 + ^5484$ + IPsec Services has experienced a critical failure and has been shut down + windows, + + + + + 18105 + ^5485$ + IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces + windows, + + + + + 18104 + ^4710$ + IPsec Services was disabled + windows, + + + + + 18105 + ^4712$ + IPsec Services encountered a potentially serious failure + windows, + + +