Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Attack?

Hi, today, in a weekly check on my UTM 9, I noticed that we are receiving thousands of packages from an external ip via port 2074 as an attachment image

The firewall blocks them but it obviously consumes many resources by doing it.


Only yesterday, more than 3 million packages were blocked.


 

In the UTM, is there anything else I can do to improve the UTM's job in blocking this attack?

Tonight I will restart the ISP router but I do not think I can change something.

 

Thanks for any suggestion.

 

 



This thread was automatically locked due to age.
Parents Reply
  • the used protocol RTP let me think about some misconfigured SIP-Client?

    do you have some mobile workers using a SIP client or something like that to get phone service?

    just my thoughts...

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

Children
  • I had thought to ask our isp to block somehow this ip, but becasue we have a configuration where our pool of ip public passes transparently on the ISP router and is managed directly from our UTM, the ISP cannot help, otherwise it could have blocked this IP.

    As suggested by you the problem was a customer device from one of our partners that was incorrectly configured.

    RTP because was a  device that sends audit alerts.

    Thanks you all for your suggestions, they were very important!!!