Source IP issue. *Urgent*

Reply
Highlighted
L3 Networker

Source IP issue. *Urgent*

Hi team,

 

I am facing the source IP mismatch region .

This is the IP 41.139.156.142 which shows up from Kenya, i have confirmed from https://ping.eu  & https://threatvault.paloaltonetworks.com/ 

but in firewall traffic log it show like this IP belongs to Germany.

I have blocked this IP in policy but why it is happening ? Why firewall shows mismatch source region ?

Does someone have insight on this issue ??

PAN OS version is 8.1.10.

 

 

Thanks & Regards,
Sahithyan S
Highlighted
Cyber Elite

Re: Source IP issue. *Urgent*

@sahithyan.subbu,

On a fully updated firewall this IP address is properly mapping to Kenya as it should be. You'll want to insure that you are running the latest content updates so that you have the latest database updates. 

Highlighted
Cyber Elite

Re: Source IP issue. *Urgent*

Hello,

I have seen this in the past where one country/provider sells IP's to another. I have had to open a support case and work it that way. PAN then had to correct the database it gets from ARIN.

 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!