Can someone suggest why the ATP would report an infection coming from an external address ?
Thanks
This thread was automatically locked due to age.
Can someone suggest why the ATP would report an infection coming from an external address ?
Thanks
I'm getting the same symptoms from that same source on a UTM running firmware 9.406-3. The aptp log shows it is protocol 6 (TCP) so this is probably unrelated to the previous UDP bug. The source IP is in Saint Petersburg, Russia, which is not on my LAN.
2016:10:26-10:33:01 xxxx afcd[31823]: id="2022" severity="warn" sys="SecureNet" sub="packetfilter" name="Packet dropped (ATP)" srcip="195.62.53.168"
dstip="xxx.xxx.xxx.xxx" fwrule="63001" proto="6" threatname="C2/Generic-A" status="1" host="lock.bz" url="" action="drop"