Skip to main content
Wilnel
New Member
January 28, 2019
Question

Fortiview showing heavy dns traffic from my account

  • January 28, 2019
  • 1 reply
  • 3208 views

I have noticed from Fortiview that my user account is listed as a top source of traffic, it is coming from the primary domain controller and it is DNS traffic. I did a screenshot. the first one part marked out is my user name, the next is the primary domain controller/dns ip and the last is name of the domain controller. How do I remedy this?

    1 reply

    Dave_Hall
    New Member
    January 28, 2019

    Not sure I understand what the problem is?  Unless you took a screenshot of total traffic, it's not uncommon to see a lot of DNS traffic, though 17,651 seems excessive (which is why I thought that graph is total traffic).  I am guessing DNS is setup on the DC.  If you think there is an issue, you may want to check the DNS settings/logs on the DC and/or check your workstation for DNS resolution issues and/or physical cable/NIC issues (e.g. duplex/speed/faulty wiring/cable).  I am going to assume the DC is in separate subnet than your workstation?

    Wilnel
    WilnelAuthor
    New Member
    January 28, 2019

    yes the dc is on a separate subnet from my workstation. Also it gets well to at least 21000 and thats every hour.