Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

An attempt to communicate with a botnet or command and control server has been detected.

hi,

can sophos please advise on how to troubleshoot this kind of errors ?

this alert comes to administrators/clients and looks severe

when you click show more info in central there is no more info

when you go in the XG or XGS in advanced threat protection, most of the times there is no mention of a botnet and in most cases the threat ip is 8.8.8.8

please advise on how we troubleshoot this kind of error.



This thread was automatically locked due to age.
Parents
  • Geiasou Ioannis and welcome to the UTM Community!

    Please insert a picture of the warning you receive.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

    My point is that since i am receiving an alert like this, and the client receives a copy of this alert, I need to be able to trace it to the exact source. the current alerting does not lead to the source of the alert .

    please suggest the correct path to troubleshoot this kind of alerts, from alert to device in my network that triggered it.

Reply
  • Hi,

    My point is that since i am receiving an alert like this, and the client receives a copy of this alert, I need to be able to trace it to the exact source. the current alerting does not lead to the source of the alert .

    please suggest the correct path to troubleshoot this kind of alerts, from alert to device in my network that triggered it.

Children