This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I see this in the firewall log some days for a few weeks many entries

i don't know how this private ip address can be trying this, it also is nothing close to our internal ip scheme

Default DROP DNS 192.168.53.1 :53→x.x.x.x(my public ip) :63923 len=73 ttl=51 tos=0x00 srcmac=c4:17:fe:fe:c9:b6 dstmac=0:1a:8c:17:5f:52


i think the src mac is from Hon Hai Precision Ind. Co.,Ltd. (what do they make)

i have tried making firewall rules to drop and not log or reject and not log, how can i stop this from showing in log so it is not so big when iam trying to find something

have see this on 8.305 and still on 8.306 astaro 320 device


This thread was automatically locked due to age.
Parents
  • Barry, it's difficult to get much information from Live Log lines.  Please show the same line from the full log file.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Barry, it's difficult to get much information from Live Log lines.  Please show the same line from the full log file.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data