This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issue with Source and Destination being switched in Reports

Hi everyone.

I'm currently experiencing the odd situation that in "Reports > Applications & web" - as well as the traffic summaries at the firewall rules, the "Source zones/countries" and "Destination zones/countries" are switched in regards to the origin and amount of ingress, resp. egress data.

Firewall rules all work as expected in regards to the direction traffic is going/filtered/forwarded and so are the entries in the "Log viewer".

In this example, I'm tracking the data for "Twitch Video Streaming" which should originate from WAN and go to LAN, but the report shows the opposite:

Similarly the source and destination countries are switched, with my internal LAN IP addresses shown as "Reserved" under "Source countries":

I have the suspicion that this is a result of how I switched the default LAN and WAN port assignments after installing Sophos XG Home on my Protectli FW4B - as the initial assignments were the opposite of the labels on the appliance (Sophos XG assigned WAN to the port labelled LAN and vice versa).

Now, while the firewall (running SFOS 17.5.9 MR-9) is still working and protecting my home network and devices as intended, I'm at a loss on how to fix this issue, as it renders reports odd to parse.

Thanks in advance for your support.



This thread was automatically locked due to age.
  • Jan,

    if you switched the LAN and WAN port, I suggest you to reset the logging partition via cli

    option 5 and then option 4 (flush device reports).

    Let us know if it works.

    Regards

    • Hi Luk,

      Thanks for the input.

      Unfortunately, the issue persists even after flushing the device reports as per your instructions.

      Regards
      Jan

      • Going back to your original question and reading it more carefully:

        if the service you are invetigating is a video streaming, you have a LAN to WAN firewall rule and not vice-versa, so the reporting is correct. WAN to LAN is only incoming traffic for allowing external users to access your internal resources.

        • Hi Luk,

          Thanks for clearing that up.

          I'll keep in mind that the reporting counts traffic to the zone initiating the traffic.

          Regards
          Jan