Hello guys, I have a problem like this, one of the interfaces Sophos UTM 9201-23, it generates a flood of incoming traffic that sends me into the network block (see attachment).
So the question is, at the level of the log, reports the firewall there is something I can be of help to understand what type of traffic and where they come from these megabytes of data?
Obviously, I am also analyzing the web server that is located on the vlan 30 that is compromised.
Thank you for your help.
This thread was automatically locked due to age.