How to find out the real source of logged application?
We are seeing a lot of blocked and passing applications in the Security Log > Application Control related to our domain controller server's IP. Tor2Web, Opera Turbo, Win_Media, WhatsUp, Gtalk, etc. These events are reported as originating (Source IP) from our DC, which is not realistic. I'm assuming that these applications are running in the local network and when they need to go outside into internet they send DNS queries into our DC (which works as local DNS and has forwarders pointing to our ISP's DNS IPs). Our DC then forwards these requests to ISP DNS servers and then Fortigate logs such requests as originating from our DC.
The problem is that we are getting reports about a "suspicious" activity on our DC from the company which is providing technical support for our Fortigate units and we have to deal with such reports by our security procedures, but if this is a misleading information from Fortigate itself, we can't do anything. I have asked support providers to file a request with Fortinet and they said that Fortinet couldn't answer what is the exact source of those logged events. So i'm trying to ask in the forums maybe someone can confirm my assumptions and maybe even explain how can i find the real source of those applications in our network.
