This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ATP Alert Generated for DNS Lookup of hosts specified in UTM Block Rule.

I run Sophos UTM 9.705-3 pointing in to an Internal Sink Hole DNS Server.

The first rule of my UTM blocks https to a large number of DNS over HTTPS Servers, one of those DOH Servers is commons[.]host.

As of 00:08 Hrs this morning I am now getting hourly ATP alerts for my DNS Server looking up an IP associated with commons[.]host which seems to now be classified as a C2 address. The IP in question is 198.54.117[.]197 .

I know why the activity takes place, the UTM Server is refreshing the IPs associated with the FQDN specified in my block rule and as it uses an Internal DNS it is catching the lookup from the DNS server.

Is there any way I can stop these alerts in this configuration ?



This thread was automatically locked due to age.
Parents
  • Just a guess, Cyrus, that you're using a DNS Host object in your rule instead of a DNS Group object.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Just a guess, Cyrus, that you're using a DNS Host object in your rule instead of a DNS Group object.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data