Hi folks,
i have got some problem with one SG 105 (9.310-11).
Over weeks there is every hour (24/7) (inbound-) traffic for about 2 minutes.
I used fitop for logging, but i could'nt see the internal device that do this request. On eth1 (external WAN) i see this:
The Firewall starts a request from Port 4244 to destination 216.137.59.33:80 (Amazon Cloudfront Server) and then the inbound traffic starts with ~3 Mb/s for 2 minutes. It is not every time the same Cloudfront-Server-IP, sometimes it was "server-216-137-63-35.lhr3.r.cloudfront.net"
I started for every other SG-interface a iftop-window to detect the requester, but with no success: no ip has a such high bandwidth usage, when the inbound traffic is high.
I cant see anything in firewall logs (queried for: ip, port).
Questions: What could it be? Does the FW drop the packets? How do i setup the firewall-logs to make that traffic visible there?
Thanks in advance.
Regards,
Christian
This thread was automatically locked due to age.