This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

vmware server showing botnet activity during vmotion???

Has anyone ever seen a vmware esxi server show up as sending a botnet attack when running a vmotion?

10.0.3.5 is the esxi server, 10.0.1.30 is my iscsi san.  Im currently transferring a 2TB vhd to the san and the firewall reported it as a botnet attack.

The esx server is not internet facing, im sure this is a false positive. Very strange.



This thread was automatically locked due to age.
Parents
  • Hi Jaesii,
    not really answering your question, but i think it is not the very best practice to have routed vMotion or iSCSI traffic neither it is to send it through a firewall device.
    I think it is not a common use-case so bulk copy in iSCSI can be a false positive.
    Yours Lukas
Reply
  • Hi Jaesii,
    not really answering your question, but i think it is not the very best practice to have routed vMotion or iSCSI traffic neither it is to send it through a firewall device.
    I think it is not a common use-case so bulk copy in iSCSI can be a false positive.
    Yours Lukas
Children
No Data