- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS logs show different app names
Hello,
In the firewall logs, different app names appear while DNS is expected to be seen as application in internet-directed DNS traffic, what is the reason for this? Can you give information about the subject?
Best Regards,
İsmail Ürek
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ismail
Can you share a screenshot?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AEK,
As seen in the image, there are apps such as “Yahoo.Mail” and “Google Translate”.
Best Regards,
İsmail Ürek
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are right, I can see the same in my firewall logs. I also see that Googlt.Traslate app signature uses DNS UDP 53, just like regular DNS query. I guess this some DNS queries that are sent to 8.8.8.8 (google) are assimilated to Google.Translate application.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AEK ,
How can I get more precise information on the subject? How can I prevent this from showing up in the logs?
Best Regards,
İsmail Ürek
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ismail
This is just my deduction according to what I see in the logs, I don't have further information.
Hope some more experienced member can give a more precise answer.
