This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Why do blocked applications show downloaded data in daily reports

Hi folks,

I have a coupe of applications blocked by web and application policies. They show in the daily reports as being blocked.

Logviewer shows them as being blocked

The question is why do they show in the daily reports as downloading data? The amount of data which is usually between 1 and 2 MB is not the issue, it is why and how do I find which device is downloading the data?

Ian 



This thread was automatically locked due to age.
Parents Reply Children
  • Isn't Sophos XG also counting the bandwidth of retransmission's ?

    The connection would get reset by the firewall, and the application would try to re-establish the connection with the server multiple times.

    *Just a guess.

  • So that gives a false impression that the block policy isn't working if you look at the application part of the reports, not the blocked  applications. The blocked application still show in the risk part of the report which would also lead people to believe the application is not blocked.

    Ian

  • If you could create a tcpdump to such a host, we could actually see, what is going on. My first assumption is, this application tries to dial in all the time (reconnect timeout of X mins). This generates a bunch of traffic compared to "connected and sending a keep alive".