Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Why does my UTM have this site in the logs every day?

I see this site http://hostby.ups-gb.co.uk/ (77.72.82.71) in the daily reports with a large number of dropped packets. The site appears regardless of what external IP address I am connected to.

I have checked whois and it shows the site is registered to an Irish man but not much else. I have tried connecting to the site, but it is not a web site or alive as far as Safari is concerned, site not found.

Anyone with ideas as to what it is?

Ian



This thread was automatically locked due to age.
Parents
  • Some lines from the actual log may help.

  • At this stage I can only get odd lines

    17:06:15 Default DROP TCP  
    77.72.82.71 : 53256
    110.140.9.80 : 32256
     
    [SYN] len=40 ttl=244 tos=0x00 srcmac=46:f4:77:c2:18:15 dstmac=00:e0:67:08:69:51

    Ian

  • Thanks for posting that.

    So this is reported in the firewall (packet filter) log.  Honestly I wouldn't lose any sleep over it.  At the end of a typical day I'll see several thousand entries in the log from all sorts of ip's trying to connect to various ports using various protocols.  Some of these are from CDN's like Akamai or amazon, others are probably malicious connections.  The firewall is doing its job by blocking and reporting these attempts.

    There is software out there that will parse your log and generate reports/trends, but I don't believe this capability is built in to utm itself.

    My advice is to just ignore it.  If it bothers you enough, you can set up a firewall rule to drop for this specific ip, or subnet (say 77.72.82.0/24) then leave the logging box unchecked.

    Prior to getting UTM I knew there were outside attempts in, I didn't realize the scope until reviewing the logs.  The old wifi router didn't keep very good logs.

Reply
  • Thanks for posting that.

    So this is reported in the firewall (packet filter) log.  Honestly I wouldn't lose any sleep over it.  At the end of a typical day I'll see several thousand entries in the log from all sorts of ip's trying to connect to various ports using various protocols.  Some of these are from CDN's like Akamai or amazon, others are probably malicious connections.  The firewall is doing its job by blocking and reporting these attempts.

    There is software out there that will parse your log and generate reports/trends, but I don't believe this capability is built in to utm itself.

    My advice is to just ignore it.  If it bothers you enough, you can set up a firewall rule to drop for this specific ip, or subnet (say 77.72.82.0/24) then leave the logging box unchecked.

    Prior to getting UTM I knew there were outside attempts in, I didn't realize the scope until reviewing the logs.  The old wifi router didn't keep very good logs.

Children