Strangely enough, I have "attacks" on my Docker host (PhotonOS) from time to time, the gateway is always shown as the attacker (in this case my XG firewall with SFOS v18). Is there a reason why this happens? How do I proceed best in this case? See the report attached as PDF in this Post. There is no Oracle database behind the host, just MySQL and PostgreSQL...
5344.Intrusion attacks_18Apr2020_19Apr2020.pdf
Here are the specific logfiles from the Live Log Viewer:
This thread was automatically locked due to age.