App Control and protocol reporting WRONG!?

Dear all,

During live monitoring of especially remote users traffic and web reporting I see a lot I mean too much traffic which is accounted for dhcp and dns which makes no sense.

Eg. tdy:

Is anybody able to clarify this ?

  • Hallo,

    Maybe it's not the UTM is generating all of that traffic...  Is the DHCP server log gigantic?  On the 'Bandwidth Usage' tab in 'Logging & Reporting >> Network Usage', can you see where this traffic originates?

    Cheers - Bob

    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

    The Dhcp log not that gigantic I would say normal and unsuspicious and yes und loggind and reporting it shows the traffic whre it comes form correctly But I was curious because in Live view and the screenshot above it draws an odd image of traffic origins