This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Multiple logs of [RST] to internal IP address

Hi guys, I have posted a similar question but seemed to get no where really so just wanted to ask if anyone else could shed any light on it.

I am seeing lots of entries (below are some examples) to many internal IP address. I am led to beleive that these are just connections being reset and nothing to worry about but I wanted to stop them from being logged but haveing no success.

09:58:43 Default DROP TCP 169.47.5.241 : 443  → 10.1.3.227 : 39316 [RST] len=40 ttl=64 tos=0x00 srcmac=00:1a:8c:4c:0f:7c
09:59:03 Default DROP TCP 52.17.221.176 : 80  → 10.1.3.227 : 52362 [RST] len=40 ttl=64 tos=0x00 srcmac=00:1a:8c:4c:0f:7c

I have tried creating rules with the sources of 443 or 80 and drop with no logging but still unsucessfull.

Any suggestions?

 

Lee



This thread was automatically locked due to age.