We've activated DNS Protection yesterday eventing on our firewall and got totally wrong resolved IP-adresses.
After reverting it back to Google, the rights ones were resolved.
How should we proceed with that ?
I can provide 2 examples
We've activated DNS Protection yesterday eventing on our firewall and got totally wrong resolved IP-adresses.
After reverting it back to Google, the rights ones were resolved.
How should we proceed with that ?
I can provide 2 examples
Hi OlafPelzer
Thanks for signing up for DNS Protection EAP.
If you can send the "Feedback" from Central (available in DNS Protection pages), it would enable us to connect over Email to discuss the concern further.
Looking forward to your response. Thanks in advance.
Hi Prashil Gupta ,
done, waiting for your reply via email-channel.
Grüße
Olaf Pelzer
Hi OlafPelzer We havent received the feedback from your account yet. Can you please confirm if you submitted feedback from DNS Protection page only
Example for submitting feedback
Step1 - Click on feedback on top right bottom corner, fill fields necessary, and click submit,
Step 2 - Acknowledgement mentioning - Thank you - we really appreciate your feedback
Already sent the feedback exactly with the procedure.
Grüße
Olaf Pelzer
Unfortunately, I am not able to identify the feedback you have sent.
Please drop your feedback to dns-protection-feedback@sophos.com with all details and we will get back to you at the earliest. Thanks for your patience
What are the wrong IPs?
__________________________________________________________________________________________________________________
The incorrectly returned IPs are:
3.70.44.70
52.28.207.170
Grüße
Olaf Pelzer
Those are the DNS block page redirect IPs.
So to speak: The FQDN you try to reach is blocked, therefore we offer this IP to block it.
This is a record, blocked by DNS due the category:
Going to this IP: try http:// 52.28.207.170/
__________________________________________________________________________________________________________________
Thx Luca!
Interesting that even a ping to the external fqdns give's back these IPs.
And the questions is why these IP adresses (our own domain with a-records for customer firewalls) are categorized as "don't go to there".
I would like to see these things in the logs which should be available soon - I hope.
Grüße
Olaf Pelzer
What policy did you use?
__________________________________________________________________________________________________________________