This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

User computer using OpenDNS DNS and firewall keeps producing these alerts

Keep receiving Sophos Critical Notification Alerts emails for Intrusion Prevention Alerts


We use OpenDNS DNS Host Servers as our primary dns and secondary dns.  All these alerts are all outbound traffic from desktop computers to OpenDNS DNS Host Servers with IPv4 208.67.222.222.

This is a snapshot of the Sophos XG330 Firewall Log Viewer.



This thread was automatically locked due to age.
Parents
  • Hi,

    are you using the web proxy, the logs you supplied indicate there is no Nat rule. Did you change the ca used on some of these computers?
    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • hello;

    no. web proxy is not checked on the checkbox.  these log viewer results are filtered for Log Subtype is not Allowed and Dst IP is 208.67.222.222.

    i just enabled now web proxy on the inbound and outbound traffic firewall rule.  Also, what is the ca stands for?

  • Certificate Authority.

    The log you published shows the DNS is being provided over GoH (DNS over HTTPS).

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
No Data