In under a 24 period I have a logfile that fills up with this message:
2021:02:18-09:51:17 ast-thr-utm-001 httpproxy[16699]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="172.17.17.2" dstip="10.1.10.2" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaInterNetwo2 (Default Filtering Group)" filteraction="REF_HttCffDefauConteFilte (Default Content Filter)" size="176" request="0xd99aaa00" url="https://10.1.10.2/" referer="" error="" authtime="0" dnstime="2" aptptime="579" cattime="317" avscantime="0" fullreqtime="2413" device="0" auth="0" ua="" exceptions="" category="9998" reputation="unverified" categoryname="Uncategorized" country="N/A"
Our core switch is the 172.17.17.2
10.1.10.2 is not a valid IP address on our network
What do you suppose the best way to try to track down the source of this is?
Thank you,
Tim
This thread was automatically locked due to age.