Skip to main content
badrgb
Visitor III
May 31, 2022
Solved

Logs to a destination port that not configured

  • May 31, 2022
  • 1 reply
  • 974 views

Hello,

I need your help to understand some logs for a rule : 

For example my rule contain :

 

Src : IP_A, IP_B ...; Dst : IP_O, IP_Z, Service ; ftp(21),telnet(23)and tcp 6058

 

in my logs on the forianalyzer I can some others dst port value.

 

It's possible? There are some explinations for that?

 

Thank you 

Best answer by badrgb

Good morning,

I think the only explination is the presence of the ftp in my rule.

1 reply

badrgb
badrgbAuthorAnswer
Visitor III
June 1, 2022

Good morning,

I think the only explination is the presence of the ftp in my rule.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!