I've seen the log message like this.
Technical Tip: Threat 131072 is seen in logs when ... - Fortinet Community
I don't know what should I do next.
Could you please explain it for me?
Do you have UTM enabled on the policy where these logs are originating from? If not its just the log messages stating a firewall connection was blocked due to policy.
Hi Graham
Yes, I do I've enabled UT on the policy. What should I do next? Skip this message or other solutions.
Can you validate the denied traffic is expected to be denied? If so, we can just ignore this as a normal traffic deny log.
Hi
Please find attached the details below.
I think it's a ms teams session but I don't know is it important?
As per the log, the policy ID is "0", which is the default deny policy and it won't have UTM. Can you check the actual policy created between the source and destination interface and see if MS-Teams is allowed in that policy?
only allowed for 80 and 443 services.
There's your answer! If you're only allowing port 80 and 443, anything else will be blocked. Your logs above are showing port 3478 is being blocked.
So either allow it or don't but if you don't you will see those log messages.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.