This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Malicious?

Hi There,

 

Just saw this on our Web Protection > Top Users By Traffic

 

Any idea why is it showing a long string of lines or possibly a domain instead of an IP? 

Is this a compromised machine?

Is this a something that they're trying to access?

Is this the user being on a VPN? 

 



This thread was automatically locked due to age.
Parents
  • Well we a few internal vlan including the 172.16.0.0 network which as you can see on the first image. 

    We have internal corporate, IT, management, and four student vlan ( different courses )

    We have DNS/DHCP server for corporate and no for student. The DHCP for student is being handle by the firewall and no reverse lookup as you can see. 

     

    I was on the impression that it only shows internal IP address and if something like this shows is that the machine is compromised. 

     

     

Reply
  • Well we a few internal vlan including the 172.16.0.0 network which as you can see on the first image. 

    We have internal corporate, IT, management, and four student vlan ( different courses )

    We have DNS/DHCP server for corporate and no for student. The DHCP for student is being handle by the firewall and no reverse lookup as you can see. 

     

    I was on the impression that it only shows internal IP address and if something like this shows is that the machine is compromised. 

     

     

Children
  • I asked about 'Allowed Networks' because I wanted to confirm that you had nothing in there that would open you to an external client.  This would include the Default Profile and any other Web Filtering Profile(s) that you have defined.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA