Hi,
Our UTM allow all outgoing connection from the internal network, but still I can see somoe drop Packets from the internal servers to the internal IP of the UTM,
if I go to these servers and try to access any htps or http site I can open them without any problem! should we ignor this?
this is one example:
2016:08:22-02:36:55 securitysrv1-1 ulogd[14154]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="00:24:e8:3b:82:20" dstmac="00:1a:8c:f0:0f:a1" srcip="10.0.10.11" dstip="10.0.10.1" proto="6" length="52" tos="0x00" prec="0x00" ttl="128" srcport="443" dstport="27536" tcpflags="ACK FIN"
or this one:
2016:08:22-01:34:04 securitysrv1-1 ulogd[14154]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:1e:c9:f7:c9:b3" dstmac="00:1a:8c:f0:0f:a0" srcip="10.0.10.183" dstip="10.0.10.1" proto="6" length="52" tos="0x00" prec="0x00" ttl="64" srcport="80" dstport="29619" tcpflags="ACK FIN"
This thread was automatically locked due to age.