Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ATP reporting source as external address

Can someone suggest why the ATP would report an infection coming from an external address ?

 

Thanks

 



This thread was automatically locked due to age.
Parents
  • we have the same warning since yesterday

    and if i reset the warning it pups up again every few hours

    and if i take look at the firewall log i see the last 3 entries are from an internal client to this IP 195.62.53.168 over Port 137.

    so i scanned this internal computer for virues and none of 4 av scanners did find anything.

    should i be worried?

Reply
  • we have the same warning since yesterday

    and if i reset the warning it pups up again every few hours

    and if i take look at the firewall log i see the last 3 entries are from an internal client to this IP 195.62.53.168 over Port 137.

    so i scanned this internal computer for virues and none of 4 av scanners did find anything.

    should i be worried?

Children
  • I'm not seeing these NETBIOS calls at any customer site.  I am seeing HTTP/S responses where NAT is in use instead of Webserver Protection.

    I'd be tempted to do a packet capture of that traffic to see what's being requested.  Since this just started in the last few days, I wouldn't be surprised if the scanners can't see the problem yet.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?