Skip to main content
CAD
New Member
February 25, 2016
Question

Report in local traffic

  • February 25, 2016
  • 1 reply
  • 8140 views

Hello Everyone,

I want some one explain me the below report i found it in Log&report in traffic Log in Local traffic  section:

 

Source

Destination

Application Name

Sent/Received

Threat

Action

Source country

77.72.xx.xx

My Public IP address

Udp/25497

0B/0B

131072

Deny

Netherlands

52.8.x.x

My Public IP address

Ping

92B/92B

 

Accept

United state

218.189.x.x

My Public IP address

Ping

840B/840B

 

Accept

Hong Kong

58.218.x.x

My Public IP address

SQUID

0B/0B

 

Deny

China

My computer

192.168.1.255

netbios forward

0B/0B

 

Deny

Reserved

    1 reply

    CAD
    CADAuthor
    New Member
    February 25, 2016

    Sorry i will upload table again:

     

    thanks And Regards,

    AtiT
    New Member
    February 25, 2016

    Hello,

    Local-in security policies are policies the control the flow of internal traffic. Traffic from/to your FotiGate.

     

    What you see in the above table is that the IP address 77.72.xx.xx wanted to communicate with the IP address of your FortiGate on the UDP port 25497 and it was blocked.

     

    Also your computer is sending broadcast netbios packets to all devices on the 192.168.1.0/24 subnet and the FortiGate blocked that communication.

    CAD
    CADAuthor
    New Member
    February 25, 2016

    thanks for reply,

     

    (IP address 77.72.xx.xx wanted to communicate with the IP address of your FortiGate on the UDP port 25497 and it was blocked.). 

    This means that 77.72.xx.xx trying to penetrate my firewall?   thanks