Question
TCP traffic for IP address 1.1.1.1
After the installation of FortiClient version 3.0.595 on my notebook I began to see TCP traffic for the IP address 1.1.1.1. I tried to scan my PC for a possible trojan but I didn' t find anything. Then, looking at the connections list, I discovered that the application FortiProxy.exe seems to be responsible for this traffic. Putting a firewall rule to block it produce a log entry like this: proto=TCP service= status=deny src=192.168.1.10 dst=1.1.1.1 src_port=48246 dst_port=37955 server_app=1 pid=-1 app_name=" " traff_direct=OUT block_count=1 logon_user= msg=" blocked traffic" with the src_port and dst_port changing all the time. As this behavior is very peculiar I' d like to know if some has seen something similar. Thank you!
