I have noticed from Fortiview that my user account is listed as a top source of traffic, it is coming from the primary domain controller and it is DNS traffic. I did a screenshot. the first one part marked out is my user name, the next is the primary domain controller/dns ip and the last is name of the domain controller. How do I remedy this?
Not sure I understand what the problem is? Unless you took a screenshot of total traffic, it's not uncommon to see a lot of DNS traffic, though 17,651 seems excessive (which is why I thought that graph is total traffic). I am guessing DNS is setup on the DC. If you think there is an issue, you may want to check the DNS settings/logs on the DC and/or check your workstation for DNS resolution issues and/or physical cable/NIC issues (e.g. duplex/speed/faulty wiring/cable). I am going to assume the DC is in separate subnet than your workstation?
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
yes the dc is on a separate subnet from my workstation. Also it gets well to at least 21000 and thats every hour.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1738 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.