Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Continously DNS connect to failed error log & Virus_sample_uploader

2023:10:26-14:56:01 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:56:01 user /usr/sbin/cron[3877]: (httpproxy) CMD (/var/chroot-http/usr/bin/virus_sample_uploader -p /var/chroot-http)
2023:10:26-14:57:11 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:58:21 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:59:31 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:00:01 user /usr/sbin/cron[4524]: (root) CMD (/var/mdw/scripts/pmx-blocklist-update)
2023:10:26-15:00:01 user /usr/sbin/cron[4529]: (root) CMD ( /usr/local/bin/reporter/system-reporter.pl)
2023:10:26-15:00:01 user /usr/sbin/cron[4528]: (root) CMD ( /var/chroot-http/var/sandboxd/tools/clear_cache_data.plx)
2023:10:26-15:00:01 user /usr/sbin/cron[4531]: (root) CMD ( /var/chroot-httpd/var/webadmin/extra/httpd_session_cleanup)
2023:10:26-15:00:01 user /usr/sbin/cron[4533]: (root) CMD ( /usr/local/bin/rpmdb_backup )
2023:10:26-15:00:41 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:56:01 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:56:01 user /usr/sbin/cron[3877]: (httpproxy) CMD (/var/chroot-http/usr/bin/virus_sample_uploader -p /var/chroot-http)
2023:10:26-14:57:11 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:58:21 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-14:59:31 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:00:01 user /usr/sbin/cron[4524]: (root) CMD (/var/mdw/scripts/pmx-blocklist-update)
2023:10:26-15:00:01 user /usr/sbin/cron[4529]: (root) CMD ( /usr/local/bin/reporter/system-reporter.pl)
2023:10:26-15:00:01 user /usr/sbin/cron[4528]: (root) CMD ( /var/chroot-http/var/sandboxd/tools/clear_cache_data.plx)
2023:10:26-15:00:01 user /usr/sbin/cron[4531]: (root) CMD ( /var/chroot-httpd/var/webadmin/extra/httpd_session_cleanup)
2023:10:26-15:00:01 user /usr/sbin/cron[4533]: (root) CMD ( /usr/local/bin/rpmdb_backup )
2023:10:26-15:00:41 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:01:01 user /usr/sbin/cron[4713]: (root) CMD (/usr/local/bin/create_rrd_graphs.plx --mode daily,weekly,monthly,yearly --type sandstorm_combined,sandstorm_web,sandstorm_email)
2023:10:26-15:01:01 user /usr/sbin/cron[4714]: (root) CMD (/sbin/audld.plx --trigger)
2023:10:26-15:01:20 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:02:01 user /usr/sbin/cron[4935]: (root) CMD ( nice -n19 /usr/local/bin/gen_inline_reporting_data.plx)
2023:10:26-15:02:30 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:03:40 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:04:50 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:05:01 user /usr/sbin/cron[5123]: (root) CMD ( /usr/local/bin/reporter/system-reporter.pl)
2023:10:26-15:05:01 user /usr/sbin/cron[5128]: (root) CMD (/usr/local/bin/create_rrd_graphs.plx --mode daily,weekly,monthly,yearly --type sandstorm_combined,sandstorm_web,sandstorm_email)
2023:10:26-15:05:01 user /usr/sbin/cron[5130]: (httpproxy) CMD (/var/chroot-http/usr/bin/virus_feedback_uploader)
2023:10:26-15:06:01 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:06:01 user /usr/sbin/cron[5298]: (httpproxy) CMD (/var/chroot-http/usr/bin/virus_sample_uploader -p /var/chroot-http)
2023:10:26-15:07:01 user dns-resolver[5043]: Updating REF_NetDnsResolver1a :: resolver1.ast.ctmail.com
2023:10:26-15:07:11 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:07:21 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:08:31 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:09:42 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:09:42 user dns-resolver[5043]: Updating REF_NetDnsIPrep3t :: iprep3.t.ctmail.com
2023:10:26-15:09:52 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:10:01 user /usr/sbin/cron[5548]: (root) CMD (/var/mdw/scripts/pmx-blocklist-update)
2023:10:26-15:10:01 user /usr/sbin/cron[5547]: (root) CMD ( /usr/local/bin/reporter/system-reporter.pl)
2023:10:26-15:11:02 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:12:12 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:13:23 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:14:23 user dns-resolver[5043]: No change to REF_NetDnsResolver1a :: resolver1.ast.ctmail.com
2023:10:26-15:14:33 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:15:01 user /usr/sbin/cron[5973]: (root) CMD ( /usr/local/bin/reporter/system-reporter.pl)
2023:10:26-15:15:01 user /usr/sbin/cron[5972]: (root) CMD ( /usr/local/bin/rpmdb_backup )
2023:10:26-15:15:33 user dns-resolver[5043]: Updating REF_NetDnsResolver1a :: resolver1.ast.ctmail.com
2023:10:26-15:15:43 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:15:53 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:16:01 user /usr/sbin/cron[6140]: (root) CMD (/sbin/audld.plx --trigger)
2023:10:26-15:16:01 user /usr/sbin/cron[6141]: (httpproxy) CMD (/var/chroot-http/usr/bin/virus_sample_uploader -p /var/chroot-http)
2023:10:26-15:16:20 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:17:01 user /usr/sbin/cron[6321]: (root) CMD ( nice -n19 /usr/local/bin/gen_inline_reporting_data.plx)
2023:10:26-15:17:30 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:18:41 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:18:41 user dns-resolver[5043]: Updating REF_NetDnsResolver2a :: resolver2.ast.ctmail.com
2023:10:26-15:18:51 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:20:01 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:20:01 user /usr/sbin/cron[6536]: (root) CMD (/var/mdw/scripts/pmx-blocklist-update)
2023:10:26-15:20:01 user /usr/sbin/cron[6544]: (root) CMD ( /usr/local/bin/reporter/system-reporter.pl)
2023:10:26-15:20:01 user /usr/sbin/cron[6546]: (httpproxy) CMD (/var/chroot-http/usr/bin/virus_feedback_uploader)
2023:10:26-15:21:11 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:22:21 user dns-resolver[5043]: DNS server failed to contact!
2023:10:26-15:23:32 user dns-resolver[5043]: DNS server failed to contact!

Hello guys,

I am completely on Sophos products and firewall themes.

I am getting continously this error from our sophos firewall. 

I have two question here.

1- virus_sample_uploader is trusty ?

2- Why am I getting continously "DNS server failed to contact error " log?

Is there anyone who can help me?

Best regards,

Hasan



This thread was automatically locked due to age.
Parents
  • Hello Hasan, 

    Thanks for reaching out to Sophos Community. 

    Are you using Sophos UTM or Sophos XG/S Firewall? 

    Do you happen to experience connectivity or DNS resolving issues while having the log messages above? Could you show yourr DNS and NTP settings? 

    Regards,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hello Raphael ,

    thanks for you replying to me.

    We are using UTM 9.

    I have just started to work this company and I did not experience these.

     

    in forwarders there are openvpncloud and google dns entries.

    static entries are empty

    request routing from local to our dc machine.

    ntp settings are so;

    please let me know if you need further information.

    btw virus_sample_uploader is a known thing?

    Best regards,

    Hasan

Reply
  • Hello Raphael ,

    thanks for you replying to me.

    We are using UTM 9.

    I have just started to work this company and I did not experience these.

     

    in forwarders there are openvpncloud and google dns entries.

    static entries are empty

    request routing from local to our dc machine.

    ntp settings are so;

    please let me know if you need further information.

    btw virus_sample_uploader is a known thing?

    Best regards,

    Hasan

Children
No Data