Skip to main content
esfa101
New Member
May 4, 2016
Question

How to find out the real source of logged application?

  • May 4, 2016
  • 9 replies
  • 9297 views

We are seeing a lot of blocked and passing applications in the Security Log > Application Control related to our domain controller server's IP. Tor2Web, Opera Turbo, Win_Media, WhatsUp, Gtalk, etc. These events are reported as originating (Source IP) from our DC, which is not realistic. I'm assuming that these applications are running in the local network and when they need to go outside into internet they send DNS queries into our DC (which works as local DNS and has forwarders pointing to our ISP's DNS IPs). Our DC then forwards these requests to ISP DNS servers and then Fortigate logs such requests as originating from our DC.

 

The problem is that we are getting reports about a "suspicious" activity on our DC from the company which is providing technical support for our Fortigate units and we have to deal with such reports by our security procedures, but if this is a misleading information from Fortigate itself, we can't do anything. I have asked support providers to file a request with Fortinet and they said that Fortinet couldn't answer what is the exact source of those logged events. So i'm trying to ask in the forums maybe someone can confirm my assumptions and maybe even explain how can i find the real source of those applications in our network.

    9 replies

    esfa101
    esfa101Author
    New Member
    May 11, 2016

    Wonderful support..

    emnoc
    New Member
    May 11, 2016

    Qs:

     

    1> do you have the fwpolicy-id?

     

    2> do you have logging all on those firewall-ID(s)?

     

    FWIW

     

    The fortiOS FW logs are very very  informational and will provide you even the pre-SNAT ipv4-address if you have NAT involved.

     

    if they are originating from within the DC, than you can easily gather the src_address.

     

     

    Ken

    esfa101
    esfa101Author
    New Member
    May 11, 2016

    1. Where can i find this ID? I'm looking at the Security Log > Application Control (which is where those applications are reported).

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!