I've set up reverse DNS for our network, and Sophos (being the primary DNS) has the correct forwarding to our network DC (which holds the reverse records).
Now most of the time the UTM logs (be it actual logs, information in the flow monitor or theā¦