Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Why ICMP traffic originated by the appliance is logged in IPS?

The IPS continuously logs the detection of an ICMP ('host unreacheable') whose source is the firewall itself, marking it as reconnaissance attack. The ICMP is originated because of an host in one zone that trie to contact a switched-off host in another zone. The XG firewall then sends the ICMP to the originating host. This is uncommon. Normally a firewall considers its traffic secure and unrestricted. 



This thread was automatically locked due to age.
  • Hi,

    I guess you have configured Anti DoS for ICMP Flood Protection. You can check that by navigating through

    System > System Services > DoS & Spoof Protection>DoS Settings>ICMP/ICMPv6 Flood.

    If you are using this, all the ICMP communication will be logged, reported and filtered explicitly.

    Thanks

    Sachin Gurung

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.