Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Weekly executive report shows external IP adresses as dropped source hosts

In the weekly executive report 5 of the 10, TOP10 dropped source hosts, are external ip addresses. This seems strange as I would only expect internal or VPN ip addresses in this list. What is the explanation for these external ip addresses and is it something that should be investigated further? Asked this question to the paid support options but they haven't comeback with a answer in 2 days. And at the moment their entire support system seems to be broken so I thought I would ask the question here.



This thread was automatically locked due to age.
Parents
  • Hoi Niels and welcome to the UTM Community!

    I would expect virtually all Dropped Source Hosts to be external IPs belonging to what may be attackers trying to access your internal network.  Or are you seeing IPs on your External interface being dropped?

    Cheers - Bob

Reply
  • Hoi Niels and welcome to the UTM Community!

    I would expect virtually all Dropped Source Hosts to be external IPs belonging to what may be attackers trying to access your internal network.  Or are you seeing IPs on your External interface being dropped?

    Cheers - Bob

Children