Hi, I am using opendns for my forwarder and I am constantly being warned about botnet activity. However ATP is completely silent.
I did get a warning about DNS query to a botnet site from ATP a few days ago but nothing since then. Upon detection, ATP redirects to a generic sophos website to download the freeware version of sophos AV.
Questions:
1. I am wondering how efficient is ATP at detecting botnet activity?
2. UTM redirecting to a generic sophos AV site doesn't make a lot of business sense. Perhaps a sales pitch to upgrade to Endpoint Protection would be more appropriate with a link to free sophos scanner.
The sophos AV scanner failed to find any viruses on the computer that made the DNS query to the botnet server so it was a false positive[:S] However opendns is still complaining about botnet activity on my network[:$]
Regards
Bill