Solved

Fortigate alerts

Posted on 2014-04-24
6
854 Views
Last Modified: 2014-05-18
Hi Experts,

I have some alerts sent from my firewall fortigate 80c.
The alert is :
Message meets Alert condition
date=2014-04-24 time=16:41:19 devname=WRWOHAB_DKG3_MASTER device_id=FG200B3912611717 log_id=0022000003 type=traffic subtype=violation  pri=warning status=deny vd="root" src=10.1.4.29 srcname=10.1.4.29 src_port=63439 dst=23.55.226.116 dstname=23.55.226.116 dst_country="United States" src_country="Reserved" dst_port=80 service=HTTP proto=6 app_type=N/A duration=0 rule=58 policyid=58 identidx=0 sent=0 rcvd=0 shaper_drop_sent=0 shaper_drop_rcvd=0 perip_drop=0 shaper_sent_name="N/A" shaper_rcvd_name="N/A" perip_name="N/A" vpn="N/A" vpn_type=UNKNOWN(65535) vpn_tunnel="N/A" src_int="port14" dst_int="port16" SN=190684789 app="N/A" app_cat="N/A" user="N/A" group="N/A" msg="N/A" carrier_ep="N/A" profilegroup="N/A" subapp="N/A" subappcat="N/A"

Can you help me with this ?
I want to know what kind of traffic this is.
0
Comment
Question by:Eprs_Admin
  • 4
  • 2
6 Comments
 
LVL 11

Accepted Solution

by:
Miftaul earned 500 total points
ID: 40020443
http traffic to 23.55.226.116  is blocked from source host at IP address 10.1.4.29.

This is due to your firewall rule 58 which you created. Did you set any Content Filtering or GeoIP on your Fortigate.
0
 

Author Comment

by:Eprs_Admin
ID: 40026651
Yes I did this filters.
But for me it is not clear which application or service want to connect to this IP.
0
 
LVL 11

Assisted Solution

by:Miftaul
Miftaul earned 500 total points
ID: 40026866
We need to check the host (10.1.4.29) to find which service used port 63439.

We could use packet filter on the Fortigate or see application flow monitor.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:Eprs_Admin
ID: 40026887
which tool I can use as application flow monitor?
Can I check this remote too ?
0
 

Assisted Solution

by:Eprs_Admin
Eprs_Admin earned 0 total points
ID: 40029686
ok now I have tested some more.
we opened a site like : www.diablo-3.net
Here is a lot of advertisment and in the bottom of the browser I could see something loading : js.adscale.de and some other sites loaded in the background.

With netsat -o -t I hava checked the connections and the PID.
The PID was always my AVP from Kaspersky, this the webcontrol.
If you don´t have webcontrol enabled, the PID is always your browser.

Now I know it has to do with ads and all the popups on the sites.
But which data wants to be uploaded from my machine as source ?
Is it cookie data ?
0
 

Author Closing Comment

by:Eprs_Admin
ID: 40073019
I selected also my statement, because here is the detailed explanation why the blocks are coming up.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
As a business owner, there are many things that keep you up at night. Profit margins, employee retention, human resource protocols, whether your product or service will remain competitive. When you own or manage a technology company that operates la…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question