<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos creates &amp;quot;Auto-generated rule&amp;quot; entries in Firewall log</title><link>https://community.sophos.com/utm-firewall/f/network-protection-firewall-nat-qos-ips/130159/sophos-creates-auto-generated-rule-entries-in-firewall-log</link><description>Hello folks, 
 i&amp;#39;m testimg with SMTP settings in Sophos right now and have approximately five failed logins to the smtp sophos server. Now the source IP of my host is blocked completely by sophos. 
 In Firewall Packet Filter Log i see the following entries</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478387?ContentTypeID=1</link><pubDate>Mon, 20 Sep 2021 18:56:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2a241c13-e980-45d5-8490-7862dc890122</guid><dc:creator>Rumak18</dc:creator><description>&lt;p&gt;No, it&amp;#39;s not about DNS, although i&amp;#39;ve given you an example with DNS.&lt;/p&gt;
&lt;p&gt;It definitely concerned the whole traffic from this machine. Especially as i&amp;#39;ve seen first SMTP with 587. And that&amp;#39;s originally what i&amp;#39;ve been doing and what caused the block for 24 hours with such log files. Every blocked traffic from this machine had this id &amp;quot;60023&amp;quot; , no matter which port from this blocked machine.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478375?ContentTypeID=1</link><pubDate>Mon, 20 Sep 2021 15:31:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1a352d9f-ec2f-4262-9964-791020366675</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;&lt;span&gt;&lt;strong&gt;fwrule=&amp;quot;60023&amp;quot;&lt;/strong&gt; is new to me and not found in the documentation.&amp;nbsp; My g&lt;span style="text-decoration:underline;"&gt;uess&lt;/span&gt; is that 19.168.130.90 is set to use the UTM for DNS (dstport=&amp;quot;53&amp;quot;), but is not&amp;nbsp;included in &amp;#39;Allowed Networks&amp;#39; for DNS in WebAdmin.&amp;nbsp; If that&amp;#39;s not it, what does Sophos Support have to say?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Cheers - Bob&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478342?ContentTypeID=1</link><pubDate>Mon, 20 Sep 2021 06:55:16 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5f09934a-6713-4953-aeee-5ef0b526096d</guid><dc:creator>Rumak18</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;so here is the full log entry from&amp;nbsp;/var/log/packetfilter/2021/09/packetfilter-2021-09-17.log.gz&lt;/p&gt;
&lt;p&gt;2021:09:17-08:23:45 MYSGNAME-1 ulogd[5081]: id=&amp;quot;2001&amp;quot; severity=&amp;quot;info&amp;quot; sys=&amp;quot;SecureNet&amp;quot; sub=&amp;quot;packetfilter&amp;quot; name=&amp;quot;Packet dropped&amp;quot; action=&amp;quot;drop&amp;quot; fwrule=&amp;quot;60023&amp;quot; initf=&amp;quot;eth0.130&amp;quot; srcmac=&amp;quot;00:1b:32:56:bd:7f&amp;quot; dstmac=&amp;quot;00:1b:8c:f0:ba:20&amp;quot; srcip=&amp;quot;192.168.130.90&amp;quot; dstip=&amp;quot;192.168.130.1&amp;quot; proto=&amp;quot;17&amp;quot; length=&amp;quot;66&amp;quot; tos=&amp;quot;0x00&amp;quot; prec=&amp;quot;0x00&amp;quot; ttl=&amp;quot;64&amp;quot; srcport=&amp;quot;48055&amp;quot; dstport=&amp;quot;53&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478320?ContentTypeID=1</link><pubDate>Sun, 19 Sep 2021 12:15:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d948ae8c-c4d7-4fd8-9ca2-caa729f84ffb</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Alone among the logs, the Firewall Live Log presents abbreviated information in a format easier to read quickly.&amp;nbsp; Usually, you can&amp;#39;t troubleshoot without looking at the corresponding line from the full Firewall log file.&amp;nbsp; Please post the line corresponding to the one above.&amp;nbsp; If you prefer, obfuscate IPs like 84.XX.YY.121, 10.X.Y.100, 192.168.X.200 and 172.2X.Y.51.&amp;nbsp; That lets us see immediately which IPs are local and which are identical or just in the same subnet.&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478312?ContentTypeID=1</link><pubDate>Sat, 18 Sep 2021 21:02:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d9815f6a-be44-4405-860d-279b17ffbc27</guid><dc:creator>Rumak18</dc:creator><description>&lt;p&gt;@ Amodin:&lt;/p&gt;
&lt;p&gt;No, it&amp;#39;s no XG. IT&amp;#39;s a SG430. And in fact, this is the log. Of course, there is still some information about source MAC and target MAC, but in the end that&amp;#39;s all. And it lasted as predicated for exactly 24 hours as i&amp;#39;ve retyped too many times (5 imes?) the wrong passwort for SMTP sending with telnet. So, in fact this was a behaviour i would expect from sophos. BUT how can one revert this for specific ips.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;@Balfson:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As already written, yes, this is a copy from the firewall log (GUI) . I can send the whole line (With mac information) but i don&amp;#39;t think this will help us to stop such a rule.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Thank you to both of you!&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478305?ContentTypeID=1</link><pubDate>Sat, 18 Sep 2021 17:33:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:54b59e0f-8e58-4d2d-9baa-6dd6fa36e9eb</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;If that&amp;#39;s copied from the Live Log, show us the corresponding line from the full Firewall log file.&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos creates "Auto-generated rule" entries in Firewall log</title><link>https://community.sophos.com/thread/478242?ContentTypeID=1</link><pubDate>Fri, 17 Sep 2021 13:31:21 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c5cca94a-3502-4e93-8384-5e0a2de03080</guid><dc:creator>Amodin</dc:creator><description>&lt;p&gt;Is this XG?&amp;nbsp; The UTM logs don&amp;#39;t look like this.&amp;nbsp; If it is XG, you may want to post on their forum site.&amp;nbsp; If you are using UTM, you can post the logs here.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>