Hi,
I have Sophos UTM9. Firewall rule 141 states, to allow traffic from one internal network to two internal servers from other subnet.
However if I check logs in Sophos i see many of these:
2018:03:08-15:15:35 fw-sophos-1 ulogd[4262]: id="2002" severity="info" sys="SecureNet" sub="packetfilter" name="Packet accepted" action="accept" fwrule="141" initf="eth5" srcmac="08:5b:0e:x" dstmac="x" srcip="74.192.189.x" dstip="My Wan IP" proto="17" length="64" tos="0x08" prec="0x40" ttl="243" srcport="34692" dstport="53"
So the question is how the packet is accepted as it is destined to WAN and not a private server IP. How that firewall rule comes in action?
This thread was automatically locked due to age.