On Sat, Apr 25, 2009 at 5:16 PM, William Maddler <[email protected]> wrote:
>
> Hello all, looks like I've got a problem with the following log:
>
>
> ----------- BEGIN
> Received From: fennel->/var/log/syslog
> Rule: 40111 fired (level 10) -> "Multiple authentication failures."
> Portion of the log(s):
>
> Apr 25 18:57:56 fennel couriertcpd: LOGIN FAILED, user=user,
> ip=[::ffff:204.111.80.65]
> Apr 25 18:57:48 fennel couriertcpd: LOGIN FAILED, user=user,
> ip=[::ffff:204.111.80.65]
> Apr 25 18:57:47 fennel couriertcpd: LOGIN FAILED, user=testing,
> ip=[::ffff:204.111.80.65]
> Apr 25 18:57:48 fennel couriertcpd: LOGIN FAILED, user=user,
> ip=[::ffff:204.111.80.65]
> Apr 25 18:57:47 fennel couriertcpd: LOGIN FAILED, user=testing,
> ip=[::ffff:204.111.80.65]
> Apr 25 18:57:41 fennel couriertcpd: LOGIN FAILED, user=testing,
> ip=[::ffff:204.111.80.65]
> ----------- END
>
> Despite the alert is generated, I have no active response action.
> Active respose is working fine for other alerts.
>
> I'd say the cause for this behaviour is that "::ffff:". Is someone else
> having same problem? Any clue?
>
> Thanx
> Maddler
>
>

I don't use active response, but I've seen issues using similar IPs in rules.
dan

Reply via email to