This thread was automatically locked due to age.
Firewall
|
2021-01-16 16:12:26
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
37.244.28.104
|
57158
|
80
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:26
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
178.79.221.45
|
57159
|
1119
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:26
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
37.244.28.104
|
57158
|
80
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:26
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
178.79.221.45
|
57159
|
1119
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:30
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
37.244.28.104
|
57158
|
80
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:28
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
37.244.28.104
|
57158
|
80
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:28
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
178.79.221.45
|
57159
|
1119
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:27
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
37.244.28.104
|
57158
|
80
|
TCP
|
0
|
01001
|
Open PCAP
|
Could not associate packet to any connection.
|
Firewall
|
2021-01-16 16:12:27
|
Invalid Traffic
|
Denied
|
|
N/A
|
0
|
|
|
192.168.1.20
|
178.79.221.45
|
57159
|
1119
|
TCP
|
0
|
01001
|
Could not associate packet to any connection.
|
Category Games and web exceptions described in https://community.sophos.com/utm-firewall/f/web-protection-web-filtering-application-visibility-control/45070/master-list-of-web-exceptions/161552#161552
are set
FW rule from local lan src any to dest any any port is allowed outbound
Do you use DPI Engine?
Because i guess, i figured out, what World of warcraft is doing.
Before the initial logging request is started, it seems to connect to a IPaddress.
After adding this IP to the local exclusion list, its working with the exceptions, you are using.
Looking into Central Firewall reporting, using Intercept X on the endpoint, you can see, this requests are caused by blizzard: