When reviewing firewall events, specifically "No Application Rule" type, the console reports information based on the remote address but not the local address. This information would be extremely helpful to determine which AD OU that the machine which triggered the event lives in and correspondingly which Firewall policy is applied to it. Is there anyway to determine this?
Enpoint: 10.0
Enterprise Console: 5.2.1.197
This thread was automatically locked due to age.