Hi, we've got UTM 9.718 running in AWS... lately, we're seeing AWS Guard Duty events for outbound DNS, to
162.159.27.50
Which is registered to CloudFlare.
In Network Services, DNS, Forwarders, we are only using Google's DNS servers (8.8.8.8 & 8.8.4.4).
There is no firewall rule to allow outbound DNS from the internal networks.
I have no idea what is generating the traffic to 162.159.27.50. That IP does not appear in any of the firewall's logs.
We do not have Sandstorm or ATP enabled, so I can't think of what else might use it. Any ideas?
Thanks,
Barry
This thread was automatically locked due to age.