Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bobm
New Contributor III

Google found unusual traffic

Today we started getting error messages from Google saying they detected " unusual traffic" from our network, and blocking our searches. I' ve done some research, and will be looking for malware, etc on the users' PCs, but also want to look at the traffic. We' re running a 60C with minimal features running (pretty much UTM only) due to memory issues. I' m going to enable IPS for a while tomorrow to see if anything hits, but wanted to know if anyone has run across this and had any ideas on what to look for in traffic logs (apps, UDP ports, etc) since Google doesn' t give any info on destination addresses, types of traffic, etc - just " unusual" .
5 REPLIES 5
netmin
Contributor II

You could search for unusual google traffic/usage in your webfilter logs, robots on your network, etc. https://support.google.com/websearch/answer/86640?hl=en
bobm
New Contributor III

Thanks netmin, I had looked at that page, and reported the situation to Google as well. And virus scans this morning came up clean. But what I was wondering was if there was a particular signature to look for in the FGT logs - addresses, applications, UDP ports, etc. that would help me narrow down my search for the culprit. Other than just " who has the most outbound traffic" . Seems to be OK today though.
Istvan_Takacs_FTNT

" unusual traffic" can also mean that someone might' ve picket your address range to target another system. Since the attacker is not interested in flooding his/her own system with the answer, the source could be faked for something unrelated. Check the traffic log also for any " unusual traffic" coming in.
omkam

Is this related to fortigate issue?

Omkar
Omkar
netmin
Contributor II

They are mainly referring to web crawlers or robots (like click bots). That was usually http or https traffic to google servers. I would investigate 24h high or constant session counts from individual PCs (i.e. using FortiView graphs/stats on 5.2.x) or session history graphs first. FortiView does also allow for more drill down. Unfortunately they don' t state more in details _when_ one gets flagged (invalid/suspicious browser agents, constant query rates or special query types).
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors