Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

application filter events

Hey,

since we installed Sophos XG we are getting a loads of app filter events regarding GaduGadu Messenger application. Strange is that this traffic is comming from almost all users and its like 100-1000 events per few minutes. Ofcourse nobody is actually using such an application.

anyone came across this? is it just false positive alarm or should we investigate further? Thanks

anonymized event:

  • messageid="17051"
  • log_type="Content Filtering"
  • log_component="Application"
  • log_subtype="Denied"
  • fw_rule_id="40"
  • fw_rule_name="LAN to WAN"
  • fw_rule_section="Local rule"
  • user="xxxxxx@xxx.xx"
  • user_group="Open Group"
  • appfilter_policy_id="8"
  • category="Instant Messenger"
  • app_name="GaduGadu Messenger"
  • app_risk="4"
  • app_technology="Client Server"
  • app_category="Instant Messenger"
  • src_ip="xxx.xxx.xxx.xxx"
  • src_country="R1"
  • dst_ip="141.95.47.55"
  • dst_country="FRA"
  • protocol="TCP"
  • src_port="49598"
  • dst_port="443"
  • bytes_sent="0"
  • bytes_received="0"
  • status=""
  • message=""
  • appresolvedby="Signature"


This thread was automatically locked due to age.
Parents Reply Children
  • If you do some further analysis of the traffic you will find that it is not false positives but actual attempts to connect to the gagugagu servers, that is why I blocked it.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.