<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ExtremeAnalytics &amp;quot;Suspicious IP-ET&amp;quot; in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84684#M9225</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Have an entry in ExtremeManagement alarms that states the following:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Alert Name:&lt;BR /&gt;Suspicious IP-ET&lt;BR /&gt;&lt;BR /&gt;Seen Count:&lt;BR /&gt;85563&lt;BR /&gt; &lt;BR /&gt;ThreatType:IP,ThreatSubType:,ThreatSeverity:Warning,ThreatSource:ET,ThreatInitiator: 222.222.222.222, ThreatInitiatorPort: 35596, ThreatTarget: 111.111.111.111, ThreatTargetPort: 80, Value: Suspicious IP: 222.222.222.222&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
I've changed the IP address to what's actually in the log.&lt;BR /&gt;
&lt;BR /&gt;
Seems to suggest something untoward is happing to the customers IP on port 80, but not sure exactly what and how Analytics is identifying it as suspicious.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks</description>
    <pubDate>Sun, 03 Mar 2019 06:29:47 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2019-03-03T06:29:47Z</dc:date>
    <item>
      <title>ExtremeAnalytics "Suspicious IP-ET"</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84684#M9225</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Have an entry in ExtremeManagement alarms that states the following:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Alert Name:&lt;BR /&gt;Suspicious IP-ET&lt;BR /&gt;&lt;BR /&gt;Seen Count:&lt;BR /&gt;85563&lt;BR /&gt; &lt;BR /&gt;ThreatType:IP,ThreatSubType:,ThreatSeverity:Warning,ThreatSource:ET,ThreatInitiator: 222.222.222.222, ThreatInitiatorPort: 35596, ThreatTarget: 111.111.111.111, ThreatTargetPort: 80, Value: Suspicious IP: 222.222.222.222&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
I've changed the IP address to what's actually in the log.&lt;BR /&gt;
&lt;BR /&gt;
Seems to suggest something untoward is happing to the customers IP on port 80, but not sure exactly what and how Analytics is identifying it as suspicious.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks</description>
      <pubDate>Sun, 03 Mar 2019 06:29:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84684#M9225</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-03-03T06:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeAnalytics "Suspicious IP-ET"</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84685#M9226</link>
      <description>Hi Martin,&lt;BR /&gt;
&lt;BR /&gt;
if you check the alarm config you'd see that the alarm is triggered by "reputation threat detected".&lt;BR /&gt;
&lt;BR /&gt;
A search in the  XMC online help (put in the XMC IP) brings you to the "IP Reputation Dashboard" section.&lt;BR /&gt;
&lt;BR /&gt;
https://:8443/Clients/help/content/oneview/docs/analytics/analytics_tab/dashboard/c_pur_analytics_tab_dashboard.htm?#IPRep&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="9b2654a7cf2449f7ac5e6c5731f80f7f_6603803b-05fc-4faa-a4f0-5746feb76833.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/681i88CDEA7316A75B9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="9b2654a7cf2449f7ac5e6c5731f80f7f_6603803b-05fc-4faa-a4f0-5746feb76833.png" alt="9b2654a7cf2449f7ac5e6c5731f80f7f_6603803b-05fc-4faa-a4f0-5746feb76833.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
For me it looks like that the 222.222.222.222 is on the list of untrusted IPs (because it's from China ?).&lt;BR /&gt;
&lt;BR /&gt;
What I don't get is how I'd acceess this IP Reputation Dashboard because I don't see it on my XMC.&lt;BR /&gt;
&lt;BR /&gt;
-Ron</description>
      <pubDate>Mon, 04 Mar 2019 20:11:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84685#M9226</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2019-03-04T20:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeAnalytics "Suspicious IP-ET"</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84686#M9227</link>
      <description>Hi Ron,&lt;BR /&gt;
&lt;BR /&gt;
Sorry, didn't get back you to say thanks for the reply... Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Did you have any luck finding the dashboard? I'm running version 8.2.4.42 and still can't see it?&lt;BR /&gt;
&lt;BR /&gt;
Perhaps its due in a later release?&lt;BR /&gt;
&lt;BR /&gt;
Thanks</description>
      <pubDate>Thu, 28 Mar 2019 20:58:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84686#M9227</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-03-28T20:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeAnalytics "Suspicious IP-ET"</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84687#M9228</link>
      <description>Added this another post, but just repeating here for consistency:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://extreme.connectedcommunity.org/communities/community-home/digestviewer/view-question?ContributedContentKey=7b213efe-e79e-4cb3-9497-a94e15f5a9b0&amp;amp;CommunityKey=d4b57428-7c7e-4bce-886a-356352ffa2c0&amp;amp;tab=digestviewer" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extrememanagement-230297/manage-suspicious-ip-et-continuous-events-7823245&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
I've created this dashboard through the report designer, which I believe gives me the detail in what the Suspicious IP-ET events are:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="763085125f3e425a8facac07c0c4475a_03897870-906a-42bd-8816-94a3d5b345a2.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1075i23A037213276DF55/image-size/large?v=v2&amp;amp;px=999" role="button" title="763085125f3e425a8facac07c0c4475a_03897870-906a-42bd-8816-94a3d5b345a2.png" alt="763085125f3e425a8facac07c0c4475a_03897870-906a-42bd-8816-94a3d5b345a2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
And pre-built one:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="763085125f3e425a8facac07c0c4475a_cd3afc1d-c59a-441f-abda-ca6cb8cabb30.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1576i97A492E38946FF43/image-size/large?v=v2&amp;amp;px=999" role="button" title="763085125f3e425a8facac07c0c4475a_cd3afc1d-c59a-441f-abda-ca6cb8cabb30.png" alt="763085125f3e425a8facac07c0c4475a_cd3afc1d-c59a-441f-abda-ca6cb8cabb30.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 20:35:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremeanalytics-quot-suspicious-ip-et-quot/m-p/84687#M9228</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-04-09T20:35:48Z</dc:date>
    </item>
  </channel>
</rss>

