Sonicwall is reporting a possible TCP flood on our CCTV network
We have multiple Hikvision NVRs that live on the same subnet as the cameras.
The NVRs are being accessed by security and some select people other employees.

It generates a large number of bogus flood alerts, is there anyway to either filter them out, or preferably tell sonicwall that it’s normal behaviour without compromising legitimate alerts?

This is how the logs look like:

Possible TCP Flood on IF X3:V1 - src: HOST_IP:59396 dst: NVR_IP:8000
Possible TCP Flood on IF X3:V1 - src: NVR_IP:8000 dst: HOST_IP:58761 - rate: 254/sec continues

5 Spice ups

Are you sure the NVR’s don’t have access to the Internet or haven’t otherwise been compromised? Hikvision and other Chinese make CCTV equipment have shown to be some of the most cyber insecure on the market.