hy ;
i have problem in the IPS in the UTM 9 so;
the SOPHOS DROP many REQUEST COMING FORM OUR LDAP SERVER
This thread was automatically locked due to age.
hy ;
i have problem in the IPS in the UTM 9 so;
the SOPHOS DROP many REQUEST COMING FORM OUR LDAP SERVER
Does the destination IP serve as a DNS server? If you look at the log you posted the destination port is 53 (DNS). All this is saying is that something on your network made a DNS lookup for .tk domain which Sophos UTM blocks. Check out this google search "https://www.google.com/#q=tk+domain+suspicious" for more information and history.
Salut and welcome to the UTM Community!
In fact, 192.203.230.10 is one of the root name servers, so you might want to consider DNS best practice.
As Ron said, your LDAP server received a DNS request from one of your other internal devices. Since very few honorable domains are in the .tk TLD, the UTMs Advanced Threat Protection blocks such requests and records that in the Intrusion Prevention log. You might want to check the DNS log in your server to see which of your devices might have a malware infection.
Cheers - Bob