This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[9.718] odd DNS traffic to CloudFlare

Hi, we've got UTM 9.718 running in AWS... lately, we're seeing AWS Guard Duty events for outbound DNS, to

162.159.27.50

Which is registered to CloudFlare.

In Network Services, DNS, Forwarders, we are only using Google's DNS servers (8.8.8.8 & 8.8.4.4).

There is no firewall rule to allow outbound DNS from the internal networks.

I have no idea what is generating the traffic to 162.159.27.50. That IP does not appear in any of the firewall's logs.

We do not have Sandstorm or ATP enabled, so I can't think of what else might use it. Any ideas?

Thanks,

Barry



This thread was automatically locked due to age.