Hi,
we use a SG135 with SFOS 18.0.3 MR-3 and see a lot of blocked .zip and .exe files in the reports. But I can't determine the URL where the files should be downloaded. Only the dst. IP ist visable, but these are from akamai. So it ist noch possible to decide if this is wanted traffic or not.
Is there a way to see the URL?
This is the Log entry:
2020-11-23 08:01:52 Application filtermessageid="17051" log_type="Content Filtering" log_component="Application" log_subtype="Denied" fw_rule_id="7" user="" user_group="" appfilter_policy_id="7" category="File Transfer" app_name="ZIP File Download" app_risk="4" app_technology="Browser Based" app_category="File Transfer" src_ip="2.20.189.211" src_country="" dst_ip="10.1.1.1" dst_country="BEL" protocol="TCP" src_port="80" dst_port="52700" bytes_sent="0" bytes_received="0" status="" message="" appresolvedby="Signature"
Thanks in advance.
This thread was automatically locked due to age.