Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Appliance access

Hello,

what exactly does "Appliance Access" mean.

I see that again and again in the log of the Sophos XG.

This is about the NTP port or the ports 137, 68, 67.

How do I best deal with these ports.

I found a workaround for the NTP port, but the message "Appliance Access" is displayed again.

Does anyone have an idea for that?

greeting



This thread was automatically locked due to age.
Parents
  • Everything is probably working properly. If you are seeing appliance access denied, this is usually random machines on the net probing your network (your public IP address, the IP address of your firewall) by sending packets to a port to see if a service is running. The firewall appropriately drops them. The particular ports are usually tied to a service where there are (or we’re at one point) vulnerabilities on some machines/OS’s

    The other time I see this is machines on my guest network sending broadcast messages to address x.x.x.255. Again, the firewall drops the packet appropriately.

    No action needed on your part, if that’s what’s happening.

Reply
  • Everything is probably working properly. If you are seeing appliance access denied, this is usually random machines on the net probing your network (your public IP address, the IP address of your firewall) by sending packets to a port to see if a service is running. The firewall appropriately drops them. The particular ports are usually tied to a service where there are (or we’re at one point) vulnerabilities on some machines/OS’s

    The other time I see this is machines on my guest network sending broadcast messages to address x.x.x.255. Again, the firewall drops the packet appropriately.

    No action needed on your part, if that’s what’s happening.

Children
No Data