- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-28-2020 01:08 AM
Hi Team,
I have issue. One user connect to SSL VPN, and cannot ping one IP 192.168.1.11. Only one IP. after i checking at firewall, I found this users got blocking activity Threat Name virus/win32.wgeneric.ajgdai id 341892366. But when this users using mobile hotspot. him can ping this IP address 192.168.1.11.
Palo Alto PA-220
Thanks
05-01-2020 07:58 AM
Hello,
I would say investigate that node to see what is causing the alert in the AV logs. Sounds like it may be compromised?
Regards,
04-28-2020 12:14 PM
Hello,
Where is the IP he is trying to ping, on his network or on yours behind the VPN?
Please advise,
04-29-2020 04:19 PM
HIi @OtakarKlier
Thanks for reply.
He at home try to ping IP at the their office(Window server 2016) . At the office have Palo Alto firewall. I checked at firewall log, and found have threat from IP address this users.
I not sure, this threat have connection from his problem or not.
Because him problem is, cannot ping (window server 2016) when use VPN from him modem wifi, but if he using mobile hotspot and use same VPN account , he can ping all server at the office (window server 2016).
So what a question is, I found threat from log firewall from account VPN same (Personal cannot ping window server 2016), Is there a problem with the threat from log firewall ?
Thanks
#log threat
-Virus/Win32.WGeneric.ajgdai 341892366
-application ms-ds-smbv3
- port 445
04-30-2020 09:02 AM
Hello,
Is ping allowed? Is the users IP on the block list for a threat, if that is setup?
Regards,
05-01-2020 01:08 AM
Hello,
Yes it allowed to ping or access or remote. Other staff can.. just him cannot ping..
Is the users IP on the block list for a threat, if that is setup? NO.
Just him cannot ping when using wifi at home.
My question is, this problem related for threat log from firewall.? below screen shot log firewall.
05-01-2020 07:58 AM
Hello,
I would say investigate that node to see what is causing the alert in the AV logs. Sounds like it may be compromised?
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!