Hello Everyone,
I want some one explain me the below report i found it in Log&report in traffic Log in Local traffic section:
Source
Destination
Application Name
Sent/Received
Threat
Action
Source country
77.72.xx.xx
My Public IP address
Udp/25497
0B/0B
131072
Deny
Netherlands
52.8.x.x
My Public IP address
Ping
92B/92B
Accept
United state
218.189.x.x
My Public IP address
Ping
840B/840B
Accept
Hong Kong
58.218.x.x
My Public IP address
SQUID
0B/0B
Deny
China
My computer
192.168.1.255
netbios forward
0B/0B
Deny
Reserved
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Local-in security policies are policies the control the flow of internal traffic. Traffic from/to your FotiGate.
What you see in the above table is that the IP address 77.72.xx.xx wanted to communicate with the IP address of your FortiGate on the UDP port 25497 and it was blocked.
Also your computer is sending broadcast netbios packets to all devices on the 192.168.1.0/24 subnet and the FortiGate blocked that communication.
AtiT
thanks for reply,
(IP address 77.72.xx.xx wanted to communicate with the IP address of your FortiGate on the UDP port 25497 and it was blocked.).
This means that 77.72.xx.xx trying to penetrate my firewall? thanks
It depends how much logs you have like this. It can be a robot that is scanning something etc.
I can see in our LAB on the firewall that 47.88.1.138 is sending DNS requests to it. It could be anything - wrong DNS configuration, a robot that was able to ping the IP address before... it is hard to say.
AtiT
thanks again ,
is there any way or tools to know this communication.
thanks
Also ,
internal computers send Netbios Prodcast and Dhcp relay , is this normal , if no how to stopped. please advise me , my knowledge not much. thanksplease i need your assistant.
Hi,
it is a Fortinet forum not Microsoft forum. Search for netbios on the Microsoft sites or on Google to see whether it is safe to turn off netbios in your network. If I remember netbios is not used since Windows 2000 but I am not sure.
AtiT
thanks for help
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.