Setup
- SFOS 17.0.0 GA
- NAT = disabled; it is being performed by the device just upstream to the XG.
- All users are authenticated as Clientless Users.
Issue
I am observing a fair amount of unknown traffic being sourced from my WAN IP address (192.168.7.129) destined for a variety of hosts. All of this traffic shows as DENIED and is labeled as belonging to a variety of Clientless Users. A snippet of the traffic log is attached.
I masked the usernames but all other data is taken directly from the log. Also of note is the In and Out Interface fields are blank.
Any idea what this traffic is for and why it is occurring?
This thread was automatically locked due to age.