Source IP issue. *Urgent*

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Source IP issue. *Urgent*

L3 Networker

Hi team,

 

I am facing the source IP mismatch region .

This is the IP 41.139.156.142 which shows up from Kenya, i have confirmed from https://ping.eu  & https://threatvault.paloaltonetworks.com/ 

but in firewall traffic log it show like this IP belongs to Germany.

I have blocked this IP in policy but why it is happening ? Why firewall shows mismatch source region ?

Does someone have insight on this issue ??

PAN OS version is 8.1.10.

 

 

Thanks & Regards,
Sahithyan S
2 REPLIES 2

Cyber Elite
Cyber Elite

@sahithyan.subbu,

On a fully updated firewall this IP address is properly mapping to Kenya as it should be. You'll want to insure that you are running the latest content updates so that you have the latest database updates. 

Hello,

I have seen this in the past where one country/provider sells IP's to another. I have had to open a support case and work it that way. PAN then had to correct the database it gets from ARIN.

 

Regards,

  • 2177 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!