I turned on portscan notifications, and have been receiving hundreds of alerts. The strange thing is, lots of them are from internal IPs. Eg:
A portscan was detected. Details about the event:
Time.............: 2016-08-05 06:12:01
Source IP address: 192.168.1.45
--
HA Status : HA MASTER (node id: 2)
System Uptime : 1 day 18 hours 32 minutes
System Load : 0.82
System Version : Sophos UTM 9.405-5
Please refer to the manual for detailed instructions.
These are Macintosh computers.
Any ideas where I should go with this? Is it a legitimate warning or a false positive with 9.405-5?
Thanks,
James.
This thread was automatically locked due to age.