Watchguard IPS blocks help desk requests - sporadic

I have some staff members that receive a message from our Watchguard XTM 1250(enterprise firewall) when trying to submit a ticket for our IT Department. In the past this has never been an issue, but after the last 2 updates to SW they have been getting request deny notices along with an CVE event when triggered from the IPS.
As an aside, the server is completely patched and updated, along with the workstations in question running IE11.
Please see the attached image and thank in advance for any advice.
This topic first appeared in the Spiceworks Community

I have some staff members that receive a message from our Watchguard XTM 1250(enterprise firewall) when trying to submit a ticket for our IT Department. In the past this has never been an issue, but after the last 2 updates to SW they have been getting request deny notices along with an CVE event when triggered from the IPS.
As an aside, the server is completely patched and updated, along with the workstations in question running IE11.
Please see the attached image and thank in advance for any advice.
This topic first appeared in the Spiceworks Community

Similar Messages

  • Where is the help desk requester application

    All the documentation tells me how to fix it but I don't actually know
    where it is. Please help. Thanks

    Jb,
    It appears that in the past few days you have not received a response to your posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at http://support.novell.com in both the "free product support" and "paid product support" drop down boxes.
    - You could also try posting your message again. Make sure it is posted in the correct newsgroup. (http://support.novell.com/forums)
    If this is a reply to a duplicate posting, please ignore and accept our apologies and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Help Desk - Project Management Add-on

    Background:  We currently offer a third party e-commerce solution for our clients called Four51.   Four51 is integrated into our SAPB1 platform.   We provide comprehensive print managment and marketing fulfillment programs for medium and large sized organizations.  ( We have 20 associates and about 6MM in sales - size perspective )   
    1st Problem:  In support of about 100 e-commerce sites for our end clients we receive multiple help desk request daily.   We have found the B1 core does not quite fit the need to track help desk service request etc....
    2nd Problem:  In addition to the help desk service ticket issue....we also have a scheduling requirement for our ebusiness group. Example:  we have 4 site builds....I need to be able to track the estimated FTE hours to build 4 sites and then benchmark against project completed and actual FTE hours deployed.
    Sought solution:   Is there a SAPB1 Add-on that will handle help desk service request...and project scheduling....integrated of course to my Business Partner data in B1.....and provide reporting etc....
    If there is not an Add-on is there a software solution that is recommended.   Any recommendations or information would be very helpful.

    The customers might benefit from using salesforce.com and using the netweaver integration which works with 2007 SP1 and 8.8.
    Also you can suggest that they use SAP by-design if available in your market as it tends to be a very modular version of All-in-One with some nifty features and lots of flexiblity.

  • My company set up a Icloud account under their help desk email but i dont have the password to fix it so i need to be able to change the Icloud apple id to my email address but it wont let me because found my Ipad is turned on and cant change?

    My company set up an Icloud apple id under their help desk email by mistake and there isnt a password so how do i change the email address/apple id
    to my email address that i do have the password for?  I can use the Ipad for everything except the Icloud account.

    If you mean that Find My Phone is asking for a password to a different Apple ID to your current Apple ID and that ID is a previous version of your current ID, not an entirely different one.
    This feature has been introduced to make stolen phones useless to those that have stolen them.
    However it can also arise when the user has changed their Apple ID details with Apple and not made the same changes to their iCloud account/Find My Phone on their device before upgrading to iOS 7, or if you restore from a previous back up made before you changed your details and some other circumstances.
    The only solution is to change your Apple ID back to its previous state with Apple at My Apple ID using your current password, you don’t need access to this address if it’s previously been used with your Apple ID, once you have saved these details enter the password as requested on your device and then turn off "find my phone" and delete the account from your device. It may take a short while to remove the account.
    You should then change your Apple ID back to its current state, save it once again and then log back in using your current Apple ID. Finally, turn "find my phone" back on once again.
    This article provides more information about Activation Lock.
    This is answer is provided from my own database of boilerplate responses and the content was last reviewed and tested on: 2014/05/23

  • ITunes Help Desk

    Okay I will freely admit this may be more of a rant then a request but I am curious if I am doing something wrong, contacting the wrong people, saying the wrong thing... etc
    It always goes down this way:
    I have a problem with a download (latest was trying to rent the movie The Guard). Movie seemed to download but then gave error message at the end. Waited a few days, every time I logged into iTunes it downloaded another copy of the movie and gave me the same error message. Last count I had over ten versions saved on my computer.
    Go to the "report a problem" link for that purchase and fill out the information.
    Because of my previous interactions in these situations I now always tell them the same stuff up-front:
    No firewall
    No anti-virus
    Tried to download multiple times over several days but still get error
    Other purchases (before and after) downloaded and play fine
    Yet everytime what follows is a minimum of 3 if not 5+ e-mails telling me to check things like:
    1. Is your firewall set to allow content through?
    2. Have you tried disableing your anti-virus?
    3. Have you tried to log out of iTunes and log back in?
    So if I know this going in why am I here now... because this time they upped their game and in their effort to fix my problem they "deactivated all my computers".
    Now in the poor guys defense maybe there is some way that something on my account may affect one single download but no others... I guess it is possible.
    But seriously when I tell them all that stuff up front why do they always insist that the problem has to be on my end.
    Wouldn't the simple fact that I have purchased and played other iTunes Content at the same time seem to lead you to think the problem might be with the content/store not the purchaser?
    I know I am spitting in the wind. The help desk people just follow a check list.

    There is no published email address for the iTunes Store. The web forms are the only contact method provided.
    I presume you're using this page, yes?
    http://www.apple.com/support/itunes/store/browser/
    If so, try clearing your browser's cache and try the page again. If you continue to have problems with the page not displaying any categories, you might try a different web browser.
    As to your problem, what model of iPod do you have? Are you aware that rentals are only supported on the iPhone, iPod touch, iPod classic (released in September of 2007 - the older 5th-generation iPod does not support rentals), or iPod Nano (3rd generation)?

  • Grant access to help desk users to add members to distribution and security groups

    Hello,
    I am trying to create a set of help desk users that has full access to add or remove members from distribution and security groups as well as update users.  We want it to bypass owner approval and essentially allow this group to add or remove members
    in the FIM Portal and flow it down to ADS.
    This obviously works fine if one is a member of the Administrators set, but we want a second tier of power users with limitied rights compared to FIM Admins.  We have added the help desk team to the  Security Group Users and Group Users set as
    well as MPR "Security group management: Users can read selected attributes of group resources".
    The help desk users can update users in the Portal with no issue.  The can search groups with no issue but when they try to add members to a group they get the error "Access Denied".
    Any help is greatly appreciated.
    Thanks!

    I'm having very similar problem - I have users with delegated right to modify group membership only. User can add someone to group and it works fine, but when the same user is trying to remove and user from a group (even if this is the same user
    which was added a minute ago) he gets Access Denied:
    The
    request included members which the requestor is not authorized
    to add and/or remove from this group."
    It is caused by default MPR:
    Group management workflow: Validate requestor on remove member
    Question is how this activity validates this request - any insight?

  • Unable to send a security code. Please contact your help desk for assistance in FIM 2010 R2

    Hi,
    I have been Successfully registered with emailid in FIM 2010 R2 Password Registration Portal.but when go in FIM 2010 R2 Password Reset Portal and gives all right answers of questions after this gives fallowing
    error:Unable to send a security code. Please contact your help desk for assistance.
    Regards
    Anil kumar

    Hi,
    Thank's for response.
    I have been cheked mail server is UP and i am able to send mail through FIMService account.
    but this is not sending Securitycode notification to any users when i login through any user gives correct answering to the Question that i was set at registration time.this gives fallowing error:
    Unable to send a security code. Please contact your help desk for assistance
    and Eventviwer Error Below:
    The error page was displayed to the user.
    Details:
    Title: Unable to send security code
    Message: Unable to send a security code. Please contact your help desk for assistance.
    Source:
    Attributes:
    Details: Microsoft.IdentityManagement.CredentialManagement.Portal.Exceptions.OneTimePasswordDeliveryException: ValidationError:UnableToSendSecurityCode ---> System.ServiceModel.FaultException: ValidationError:UnableToSendSecurityCode
       at Microsoft.ResourceManagement.WebServices.SecurityTokenServiceClient.RequestSecurityTokenResponse(Message request)
       at Microsoft.ResourceManagement.WebServices.SecurityTokenServiceClient.RequestSecurityTokenResponse(RequestSecurityTokenResponseType request, ClientOptionsHelper clientOptionsHelper, MessageBuffer& messageBuffer)
       at Microsoft.ResourceManagement.WebServices.Client.AuthenticationRequiredException.Authenticate(AuthenticationChallengeResponseType[] authenticationChallengeResponses, MessageBuffer& messageBuffer, ClientOptionsHelper clientOptionsHelper)
       at Microsoft.IdentityManagement.CredentialManagement.Portal.Common.ResetProxy.GetChallenge(String domain, String userName, ChallengeContext gateChallengeResponse)
       at Microsoft.IdentityManagement.CredentialManagement.Portal.Common.ResetProxy.GetNextChallenge(String domain, String userName, ChallengeContext gateChallengeResponse, FaultExceptionHandlerDelegate faultExceptionHandler)
       --- End of inner exception stack trace ---
       at Microsoft.IdentityManagement.CredentialManagement.Portal.Common.ResetProxy.GetNextChallenge(String domain, String userName, ChallengeContext gateChallengeResponse, FaultExceptionHandlerDelegate faultExceptionHandler)
       at Microsoft.IdentityManagement.CredentialManagement.Portal.Components.DriverBase.GetNextGate(IGateControl currentGate)
       at Microsoft.IdentityManagement.CredentialManagement.Portal.Reset.Next()
       at System.Web.UI.WebControls.Button.OnClick(EventArgs e)
       at System.Web.UI.WebControls.Button.RaisePostBackEvent(String eventArgument)
       at System.Web.UI.Page.RaisePostBackEvent(IPostBackEventHandler sourceControl, String eventArgument)
       at System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint)
    CorrelationId:
    RequestId:
    ErrorCode: 3013
    CaughtTime: 05/02/2014 08:43:26
    Web Portal: FIM Password Reset Portal
    Session Id: 21uppbuy3vutsm55sytd4b55
    Regards
    Anil Kumar

  • Help Desk tools for deploying VDI workstations???

    Are there any tools or suggestions for simplifying the virtual desktop provisioning process?  I ask this so our help desk doesn't have to log into the View Admin portal to manage the environment or provision workstations.  I was hoping there was a resource, config wizard or web portal available to use where the View Admin console works in the background while the user requesting a VDI just inputs their desired config parameters (ie- user name, type of VDI, etc.).   Thanks in advance for your suggestions!

    user21354 wrote:
    ..a project in java ,*oracle its a web development and has given me sometime to prepare for that* , i want to ask which IDE i use for it actually me company will use eclipse for that...I'm not sure if this is what you want but the followings are good to give a try while you still have a plenty of time assigned
    Oracle JDeveloper could be a good option if you'd like to create web apps with Oracle back-end databases.
    Other IDEs like Eclipse or NetBeans.,etc are available too... just google it with "java ide", you would be surprised with the results:-)
    For more details on aforementioned tools, check this out!
    http://www.oracle.com/technetwork/index.html
    Good luck!
    HappyJay

  • Logging into home remotely - is Verizon blocking incoming connection requests?

    I'm trying to set up my computer at home so that I can access it from my in-laws, who are also FIOS customers and from my Android device via Sprint's network.   Both of these use SSH as the protocol, and on the theory that port 22 might be blocked, I set up the Actiontec to map an alternate port  (1977) to port 22 on my server.  My first attempt was to use the port forwarding capability in the router, but I have been unsuccessful in establishing a connection from outside my network.
    I've tried configuring  my server as the DMZ for the Actiontec, which makes me nervous, but I was running out of ideas.  I even turned the firewall off on the PPoE connection but that didn't help either.
    From outside my network, I can ping the WAN IP address assigned by Verizon to my router, so inbound ICMP packets are OK, at least as far as getting to the Actiontec
    I can log onto my server while on my local network, but not from outside the network.
    I'm running out of ideas.  Does anyone know of a way to dump packets coming to the Actiontec so that I can tell if the inbound TCP packets make it to my router?
    Does Verizon block inbound TCP requests for residential service?  For all ports?
                                      Thanks for any info,
                                Joe H.
    {edited for privacy}
    Solved!
    Go to Solution.

    I don't have it working yet, but I was able to run a test that forwarded the port to my laptop and I see (via wireshark) the inbound connection.  So, while I can log into my server locally, I must have some sort of firewall rule on that server that's preventing connections from the outside.
    Verizon, I apologize for implying you were blocking.   This looks like a local issue on my end.

  • Bring back the independent App for the Economist Magazine! Take it out of Newsstand! Audio version no longer downlaods! Their Help desk is incompetent!

    Using the audio version of the Economist magazine is impossible in their new Newsstand version App. It just will not download. The Economist help desk is incredibly unhelpful and incompetent. This used to be so easy when the App was independent. Several other people have given feedback requesting the old App returns and complaining the App inside Newsstand is dis-functional! Who will support me in bringing back the independent Ap? NO NEWSTAND AP TYRANNY!!

    Only the people at The Economist can choose to reprogram the app so it is out of Newstand.

  • Why my IPS - aip-ssm send requests to 80.53.146.82 port 80

    I have a web proxy ..tunnel filters...and AIP-SSM....inside of the network...i configure host service, network setting and hhtp-proxy to use my proxy when updating global corelation ...
    On proxy I allow hhtps to 204.15.82.17 ---ironport service.
    In proxy log I see that https to 204.15.82.17 is allowed and after that ips try to sending http packets to 80.53.146.82 -----I SEE in the RIPE that is AKAMAI technologies IP..address.
    What is this?
    Why my IPS - aip-ssm send requests to 80.53.146.82 port 80

    This is the new 7.x Global Correlation feature, and it is documented here:
    http://www.cisco.com/en/US/docs/security/ips/7.0/release/notes/18483_01.html#wp1161779
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_collaboration.html
    AFAIK, you can turn off this feature as per your discretion. Cisco has adapted the Ironport senderbase technology to their IPS as well. Its a pretty interesting feature, I hope it becomes as successful as the one for mail traffic.
    Please rate if helpful.
    Regards
    Farrukh

  • SMTP IPS block problem

    I setup ID 3110 (suspicious mail attachment)to deny attacker inline thinking that nobody needs to send those type of attachments and it would cut down on virus's. Worked fine until today when someone internal tried to send one and the IPS blocked my internal smtp server from going to the internet. Is there a way of setting up execptions in the IPS so that my internal IP range is allways allowed access? Or is there a better way of doing this?
    Thanks for the help.

    We've seen false positives with that signature, but YMMV...they've modified it recently so maybe it's fixed.
    anyway, to answer your question...there are two ways to handle this.
    1) Use an event filter to subtract the action from the alarm. The mail server source ip would part of the criteria in the filter. You might want to consider creating an event variable for your entire DMZ and creating an event filter that subtracts any of the "deny" actions if DMZ=source. See Event Action Rules->Even Action Filters in the IDM.
    2) add the source ip or network to the "never block addresses". See Blocking->Blocking Properties in the IDM. I don't believe this works for actions that are "deny"...you'll need an event filter for those.

  • Integration between IBM's 'eESM' help Desk and SolMan...??

    Hi All
    Hopefully someone can help we with a answer..:-))
    We are currently using IBM as external vendor to run our Service Desk.
    They are using a system called 'Manange Now' (eESM) which we think
    is about the worst help desk tool we have ever seen....!!! My question
    is does anybody have experience with interfacing eESM and SolMan..??
    IBM have just told me that currently it's not possible to interface the
    2 systems and to my knowledge that's just not true...!!!
    Please advice..:-))
    Best regards
    Peter

    Dear Peter,
    If you want to connect a third party product like a Remedy Call Tracking
    System (Peregrine ServiceCenter) to the Service Desk, use the SAP
    Business Connector. This is an infrastructure offer from SAP to export
    messages to another call tracking systems. The SAP Business Connector
    handles data structure mapping and output into the requested format
    (SMTP, HTTP).
    The transfer of messages can be triggered by a scheduled background job
    or initiated manually. The data structure for the export interface is
    determined by the SES/SIS standard.
    Requirements for implementation at the customer site
    - SAP Solution Manager up and running
    - Background job scheduled in SAP Solution Manager for export data
    - SAP Business Connector (SAP BC) up and running
    - Import of a transport into SAP BC
    - Modification / adjustment of your call tracking system to enable case
    creation based on data from SAP BC (third party consulting may be
    necessary)
    For further details see SAP Note 529754 and follow this link :
    http://service.sap.com/solutionmanager -> "Functions in Detail" ->
    "Support Area" -> "Message Handling Process"
    Check the section "Interface between Service Desk and a Third Party Call
    Tracking System "
    Hope this information helps.
    Regards
    Amit

  • How to Implement BW in IT Service Desk/IT Help Desk /IT Complain Surveillance Dept/IT Customer Support Dept?

    Hi
    If a organization have 200 to 300 daily complains of there IT equipment/Software/Network e.t.c.
    How to Implement BW in IT Service Desk/IT Help Desk /IT Complain Surveillance Dept/IT Customer Support Dept?
    Is there any standard DataSources/InfoObjects/DSOs/InfoCubes etc. available in SAP BI Content?

    Imran,
    The point I think was to ensure that you knew exactly what was required. A customer service desk can have many interpretations from a BI perspective.
    You could have :
    1. Operational reports - calls attended per shift , Average number of calls per person , Seasonality in the calls coming in etc
    2. Analytic views - Utilization of resources , Average call time and trending , customer satisfaction , average wait time
    3. Strategic - Call volumes corresponding to campaigns etc , Employee churn and related call times
    Based on these you would then have to construct your models which would be populated by data from the MySQL instance for you to report.
    Else if you have BWA you could have data discovery instead or if you have HANA - you could do even more and if you have a HANA sidecar - you technically dont need BW. The possibilities are virtually endless - it depends on how you want to drive it and how the end user ( client ) sees value in the same.

  • How to log in with my old Apple account? I forgot my pass and I did change my apple ID before canceling first?? I am from Croatia so did folow al the discussion and the to resolve the problem but no luck. Can not call from Croatia the Apple help desk

    How to log in with my old Apple account? I forgot my pass and I did change my apple ID before canceling first?? I am from Croatia so did folow al the discussion and the to resolve the problem but no luck. Can not call from Croatia the Apple help desk.i did try all the options but I can not find the phone number to call from Croatia,
    I can not change my Apple ID to the old mail (not possible!)
    The old mail don't accept the new password..
    I can not delete the Icloud all the time asking my the password of the old mail!
    I realy need help

    You can not merge accounts.
    Apps are tied to the Apple ID used to download them, you can not transfer them.

Maybe you are looking for

  • How to get the number of processor license

    Hi, SQL> select CPU_COUNT_CURRENT,CPU_CORE_COUNT_CURRENT,CPU_COUNT_HIGHWATER,CPU_CORE_COUNT_HIGHWATER,CPU_SOCKET_COUNT_HIGHWATER 2 from v$license; CPU_COUNT_CURRENT CPU_CORE_COUNT_CURRENT CPU_COUNT_HIGHWATER CPU_CORE_COUNT_HIGHWATER CPU_SOCKET_COUNT_

  • C++ Runtime Error when trying to open Adobe Acrobat

    When I try to launch Adobe Acrobat 6.0, I get the following error: Runtime Error! This application has requested the Runtime to terminate it in an unusual way. I've tried every fix I could fin on the Web including reinstalling the program. Does anyon

  • Movie Wont Play on N95 8GB just closes movie centr...

    i followed this links instructions /discussions/board/message?board.id=smartphones&message.id=80579 but when i click to open the movie in video centre and when i click on play it just goes to the main menu and does nothing. any one able to help? ive

  • My macbook pro is zoomed in and I can't fix it!!!

    I was messing with my macbook pro and it zoomed in and I can't fix it. Help!!!!!!!!

  • Very Weird Problem with Images on Websites while browsing with Safari

    Picture says it... http://home.mountaincable.net/~jameslin/1.JPG but when I open the same webpage in IE all the images load up in their proper covers just fine. Also no I haven't done any photo editing in photoshop or anything recently, this just hap