Skip to main content
Contributor III
September 23, 2008
Question

TCP traffic for IP address 1.1.1.1

  • September 23, 2008
  • 4 replies
  • 2811 views
After the installation of FortiClient version 3.0.595 on my notebook I began to see TCP traffic for the IP address 1.1.1.1. I tried to scan my PC for a possible trojan but I didn' t find anything. Then, looking at the connections list, I discovered that the application FortiProxy.exe seems to be responsible for this traffic. Putting a firewall rule to block it produce a log entry like this: proto=TCP service= status=deny src=192.168.1.10 dst=1.1.1.1 src_port=48246 dst_port=37955 server_app=1 pid=-1 app_name=" " traff_direct=OUT block_count=1 logon_user= msg=" blocked traffic" with the src_port and dst_port changing all the time. As this behavior is very peculiar I' d like to know if some has seen something similar. Thank you!

    4 replies

    abelio
    SuperUser
    SuperUser
    September 23, 2008
    Yes, that traffic to 1.1.1.1 port 80 are generated by FC internal http proxy tests, it never reach the physical network; if you use kaspersky antivirus your Fortiproxy will do some tests and finally disable itself if those tests fail; I asked support for that and they told that those should be not a problem.
    Contributor III
    September 26, 2008
    Thank you for your answer! In my case I saw that that traffic actually reach the physical network but the forticlient firewall is able to stop it. Even if I didn' t put a specific rule to stop it, it seems to last forever and it' s not only for port 80 but also for high ports. For me it is a problem because I cannot keep the firewall log enabled and because I often use a network monitor application for development purposes I will try if there is a way to disable these fortiproxy tests...
    vanc
    New Member
    September 28, 2008
    Proxy self test can be disabled in build 3.0.599 (MR7 patch-1). It also fixed the packet leakage. If you can wait for a bit more time, patch-2 will be out next week. You can try it.
    Contributor III
    September 28, 2008
    Great, thank you! I will keep the filter until the patch solve the problem. I' m also happy to know that it was really a small problem related to the forticlient and not a trojan... Regards.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!