This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I need someone to explain this for me?

Hi folks,

I am a little puzzled by a report in there XG GUI and more details in the report section. The issue is my wife MBP is shown as having been attacked by a control "nasty" using the DNS.

On my XG there are two firewall rules allowing users to access DNS, 1 in IP4 and the other in IPV6. The IP4 rule does not show any traffic. Does this mean the XG DNS proxy is not really a proxy?

Please see a report extract below.

Thank you

Ian



This thread was automatically locked due to age.
Parents
  • Basically you dont need a DNS Firewall policy because the DNS Server is setup by the ACL under Device access. 

    So if you enable for LAN DNS and your client is asking the XG to get a C2 Name of it, it will be shown as above. 

     

    Can you show us the advanced view of logviewer of this alert? 

Reply
  • Basically you dont need a DNS Firewall policy because the DNS Server is setup by the ACL under Device access. 

    So if you enable for LAN DNS and your client is asking the XG to get a C2 Name of it, it will be shown as above. 

     

    Can you show us the advanced view of logviewer of this alert? 

Children