This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos creates "Auto-generated rule" entries in Firewall log

Hello folks,

i'm testimg with SMTP settings in Sophos right now and have approximately five failed logins to the smtp sophos server. Now the source IP of my host is blocked completely by sophos.

In Firewall Packet Filter Log i see the following entries , but this concerns every packet that is now generated by 192.168.130.90.

192.168.130.1 is my sophos. 

09:16:48 Auto-generated rule UDP  
192.168.130.90 : 39846
192.168.130.1 : 53

There is no packet filter rule that corresponds with this behaviour. I guess it was created automatically for 24 hours as i have seen this behaviour for some time. But how can i revert these settings for these trustworthy hosts?



This thread was automatically locked due to age.
Parents
  • Is this XG?  The UTM logs don't look like this.  If it is XG, you may want to post on their forum site.  If you are using UTM, you can post the logs here.

    OPNSense 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | ATT Fiber 1GB
    (Former Sophos UTM Veteran, Former XG Rookie)

Reply
  • Is this XG?  The UTM logs don't look like this.  If it is XG, you may want to post on their forum site.  If you are using UTM, you can post the logs here.

    OPNSense 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | ATT Fiber 1GB
    (Former Sophos UTM Veteran, Former XG Rookie)

Children
No Data