Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Invalid Traffic Denied

In CR15iNG


There is no connectivity issue but this error appear.
Any idea to fix this.

 



This thread was automatically locked due to age.
Parents
  • Hi  

    Could you please confirm the status of PING for the WAN interface?

    Please go to System >> Administration >> Appliance Access

    What is the IP address of your WAN Interface?

    As per the logs ICMP traffic is receiving on Port B from WAN side.

    For more details on Invalid Traffic, please refer to the below article. 

    https://community.sophos.com/kb/en-us/131754

    Note: It is only critical to worry about Invalid traffic entries if there is a problem of disconnection or inaccessibility.

  • Hi,

    Ping is disabled for Wan,Dmz for security.

    Admin>appliance access>
    Lan
    Wan
    Dmz
    Vpn
    Wifi

     

    Is this a right idea?
    Got log in Every seconds.

  • Hi  

    For security reasons, you may disable ping for WAN and DMZ zone.

    As per the logs, traffic from 212.156.63.157 coming from the WAN zone and Cyberoam denied the packets as per the configuration.

    You may take access of SSH console of the Cyberoam and login to console access and execute the command to see the request from the IP.

    tcpdump 'host 212.156.63.157, if there are many request, you can notify your ISP to block the traffic from this specific IP in your WAN link

Reply
  • Hi  

    For security reasons, you may disable ping for WAN and DMZ zone.

    As per the logs, traffic from 212.156.63.157 coming from the WAN zone and Cyberoam denied the packets as per the configuration.

    You may take access of SSH console of the Cyberoam and login to console access and execute the command to see the request from the IP.

    tcpdump 'host 212.156.63.157, if there are many request, you can notify your ISP to block the traffic from this specific IP in your WAN link

Children