I have a UTM 625 and I am getting IPS logs that show the source address as my internal DNS servers. From what I can tell it is just DNS queries and there are not many packets, but was wondering if this is normal. I have IPS set to drop packets silently, but not sure why they are getting flagged.
This thread was automatically locked due to age.