Hello folks,
i'm testimg with SMTP settings right and have approximately five failed logins. Now the source IP of my host is blocked completely by sophos.
In Firewall Packet Filter Log i see the following entries , but this conerns every packet that is now generated by 192.168.130.90.
192.168.130.1 is my sophos.
There is no packet filter rule that corresponds with this behaviour. I guess it was created automatically for 24 hours as i have seen this behaviour for some time. But how can i revert these settings for these trustworthy hosts?
Alone among the logs, the Firewall Live Log presents abbreviated information in a format easier to read quickly. Usually, you can't troubleshoot without looking at the corresponding line from the full Firewall log file. Please post the line corresponding to the one above. If you prefer, obfuscate IPs like 84.XX.YY.121, 10.X.Y.100, 192.168.X.200 and 172.2X.Y.51. That lets us see immediately which IPs are local and which are identical or just in the same subnet.
What login is failing? What do you see?
Cheers - Bob
Redirect to:
https://community.sophos.com/utm-firewall/f/network-protection-firewall-nat-qos-ips/130159/sophos-creates-auto-generated-rule-entries-in-firewall-log