Event ID - PIX-5-415002

Message CodePIX-5-415002
SeverityNotification
Descriptioninternal_sig_id HTTP Instant Messenger detected - action instant_messenger_type from source_address to dest_address
ExplanationThis message is issued when the http-map port-misuse command is configured and an instant message protocol is detected.action—This can contain either: “Reset -” or “Drop -” depending upon the user-configured action.If the action is “log” then the null string """" is passed.dest_address—The destination address of the packet in which the instant messenger protocol was detected. instant_messenger_type—Indicates which type of instant messenger protocol was detected.internal_sig_id—This an internal “policy number” that can be used by developers to identify the specific policy that triggered the alert.source_address—The source address of the packet in which the instant messenger protocol was detected.
User ActionThe message indicates that a user was running an instant messenger protocol over HTTP. This may violate policy.
Reference Links

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.