- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-09-2024 05:35 AM - edited 07-09-2024 05:36 AM
We use DNS Proxy on 3 of our zones with the firewall IP as the address that the traffic is proxied to. In other words, the firewall proxies the network traffic with it's own IP address.
However, in the threat logs, we have some threats that do not show the original source IP and instead show the firewall's IP as the source address, due to the proxy.
How can I get the true source IP?
Regards and thanks in advance,
AverageTechnician
07-10-2024 03:14 AM
having sinkhole enabled will reveal the source IP as that will connect to the sinkhole IP address
to detect the malicious DNS looklup from the original client, you'd need to create a security rule from the source subnet to the proxy IP with security profiles enabled, so the original request is intercepted
07-10-2024 07:31 AM
I will go configure this and report back. Thank you very much, I thought nobody would respond.
I also read the second edition of your textbook and it was great when I got this job
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!