Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dyop_Geop
New Contributor

unknown Source Consuming bandwidth

May I ask, what could be this “viewpaulbusinezs.no-ip.org (0.0.0.0)” mentioned in the screenshot below? In the screenshot also is the configuration of the widget for your reference. How can I trace what is this or who is this?
24 REPLIES 24
Dyop_Geop

I' d suggest to read the following article first; Microsoft Seized No-IP Domains, Millions of Dynamic DNS Service Users Suffer Outage http://thehackernews.com/2014/06/microsoft-seized-no-ip-domains-millions.html Than run update virus/malware scanner on your LAN hosts. BTW, 0.0.0.0 means that the host has no published record: $ dig +short @nf1.no-ip.com viewpaulbussinezs.no-ip.org 0.0.0.0
The LAN hosts have their own virus scanner. There are a lot of them. Sadly, we don' t have like a certain standard in terms of protecting the users. Its like if we give an employee a laptop, we do the initial installations of OS and AVs, but we don' t monitor after that. So after issuing a laptop, we kinda can' t track if their AV are still up to date, or if its still installed there. etc. If you can observe the screenshots, bytes are only sent. Can we assume that the whoever this is, it is only sending requests to a certain destination and the destination is dropping these requests? Thanks Itsvan
Istvan_Takacs_FTNT

From the screenshot you included nothing indicates that the packets are getting dropped, only they are getting sent. Like emnoc suggested, if the issue happens again than run some troubleshooting commands on the FGT or turn on logging on the last implicit deny rule and analyse the logs for anything suspicious. " So after issuing a laptop, we kinda can' t track if their AV are still up to date, or if its still installed there. etc." Than Forticlient should be just perfect for you to get it installed on all of these laptops. You can even enforce FGT policy after client registration to enable access to network only if the client has updated AV signatures. http://www.forticlient.com/ " With no per-seat license fees, FortiClient takes the headaches out of managing multiple endpoints so your users & guests can work efficiently anywhere, without compromising your security. It' s the end-point solution for your FortiGate network."
Dyop_Geop

ORIGINAL: Istvan Takacs From the screenshot you included nothing indicates that the packets are getting dropped, only they are getting sent. Like emnoc suggested, if the issue happens again than run some troubleshooting commands on the FGT or turn on logging on the last implicit deny rule and analyse the logs for anything suspicious. " So after issuing a laptop, we kinda can' t track if their AV are still up to date, or if its still installed there. etc." Than Forticlient should be just perfect for you to get it installed on all of these laptops. You can even enforce FGT policy after client registration to enable access to network only if the client has updated AV signatures. http://www.forticlient.com/ " With no per-seat license fees, FortiClient takes the headaches out of managing multiple endpoints so your users & guests can work efficiently anywhere, without compromising your security. It' s the end-point solution for your FortiGate network."
Hi Istvan, thanks for the reply, will do the logging for the last implicit deny in time. As for the forticlient, I will try to push this. Kinda difficult to do this since there are a lot of clients.
emnoc
Esteemed Contributor III

I' d suggest to read the following article first; Microsoft Seized No-IP Domains, Millions of Dynamic DNS Service Users Suffer Outage http://thehackernews.com/2014/06/microsoft-seized-no-ip-domains-millions.html
Yeah but I think MS had to revert the domains back from my understanding. It was a fruitless legal claim and as silly as the former mayor bloomberg suing the gun manufacture for kill a person OP, did you find the culprit and remediated the problem? Istvan gave some good advice on run AV/MAL on the abuse machine.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dyop_Geop

Hi emnoc, not yet. Sorry I just don' t know how can i find out where this is coming from.
netmin

Does
 diag ip arp list | grep " ifname=port1 0.0.0.0"  
 
return something? If yes (a MAC address, example: ' 00:00:DE:AD:C0:DE' ), does
 diag ip arp list | grep " 00:00:DE:AD:C0:DE" 
 
show any additional information?
Dyop_Geop

ORIGINAL: netmin Does
 diag ip arp list | grep " ifname=port1 0.0.0.0"  
 
return something? If yes (a MAC address, example: ' 00:00:DE:AD:C0:DE' ), does
 diag ip arp list | grep " 00:00:DE:AD:C0:DE" 
 
show any additional information?
Hi netmin, the command doesn' t return anything. No additional information. What' s weird is that, I' m trying to sort the Top Sources by changing " src Interface" to Port1 LAN, then " Dst Interface" to " Wan1" or " Wan2" , since these are the only interfaces in use in this fortigate, the 0.0.0.0 entry DOESN' T SHOW. Its only in the condition that the Src Interface is at " PORT1" and " All" , and Dst Interface to " All" that the 0.0.0.0 entry will show.
netmin

one more GUI setting you can try (I would already have used <add your favourite swiss knife tool here> at this time) to potentially get more information about the traffic type: - set your session monitor to " Report By: All" - click on " Column settings" - add columns, such as protocol, src port, src address, dst port, dst address, etc. ... as needed. Example:
Dyop_Geop

ORIGINAL: netmin one more GUI setting you can try (I would already have used <add your favourite swiss knife tool here> at this time) to potentially get more information about the traffic type: - set your session monitor to " Report By: All" - click on " Column settings" - add columns, such as protocol, src port, src address, dst port, dst address, etc. ... as needed. Example:
Hi netmin, thanks again for your reply. and patience :) Already did what you specified, and after setting the session monitor to " Report By: All" , the " paulbusiness, etc,etc" was not shown. All that was shown are valid private ip addresses. BEFORE:
Dyop_Geop
New Contributor

AFTER:
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors