Guten Abend,
ist hier etwas dran weshalb Sophos die IP 188.114.97.3 als Malicious einstuft oder wieder ein FalsePositive?
Unser ATP der UTM9 meldet das seit Freitag bei DNS Anfragen ...
This thread was automatically locked due to age.
Guten Abend,
ist hier etwas dran weshalb Sophos die IP 188.114.97.3 als Malicious einstuft oder wieder ein FalsePositive?
Unser ATP der UTM9 meldet das seit Freitag bei DNS Anfragen ...
Die XGs sind ein wenig gesprächiger, scheint mal wieder irgendein Edge-Feature zu sein. Eventuell die automatisch angezeigten Nachrichten?
Microsoft selbst wird ja vermutlich eher nix bei Cloudflare hosten...
Regards,
Kevin
Sophos CE/CA (XG, UTM, Central Endpoint)
Gold Partner
Do the following:
Filter in logviewer for the IP (use only the string search on the top right site).
Then move to the detailed view and check, which URL was opened.
__________________________________________________________________________________________________________________
I can only see the URL when searching the IP in the Web filter logs. Over the day the fqdn changed quite a few times...
And ATP keeps banging on all our firewalls. The UTMs are relatively quiet now, but the XG/XGs are notifying every 10 minutes or so. And additionally Central mails are coming from some customers. We are totally bombed by those mails today...
Regards,
Kevin
Sophos CE/CA (XG, UTM, Central Endpoint)
Gold Partner
I can only see the URL when searching the IP in the Web filter logs. Over the day the fqdn changed quite a few times...
And ATP keeps banging on all our firewalls. The UTMs are relatively quiet now, but the XG/XGs are notifying every 10 minutes or so. And additionally Central mails are coming from some customers. We are totally bombed by those mails today...
Regards,
Kevin
Sophos CE/CA (XG, UTM, Central Endpoint)
Gold Partner