Running a UTM 425 appliance with 9.004-34 in bridged mode. Running Web, Wireless, Application, IPS services.
Over the past 2 days I've been fighting with traffic coming in from Google IP's maxing out our Internet connection.
Examples:
iad23s07-in-f17.1e100.net
iad23s07-in-f18.1e100.net
I'll attach an iftop and sample graph showing this. The UTM's internal IP (FBGUTM) is showing the destination, whereas if I look at all other traffic I can see where it is originating (like a PC on the network). I can't see where the traffic is going after it hits the UTM, as if the UTM is taking the data and doing something with it?
I've restarted the UTM and tried selectively shutting down certain services one at a time to see if has any affect but nothing. I thought maybe a stuck Up2Date download but I can't verify that.
I'm stuck how to figure out where this is coming from and why... any help is appreciated.
This thread was automatically locked due to age.