IP blocked then allowed

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

IP blocked then allowed

L1 Bithead

I'm reviewing a logs regarding a low reputation IP which in the first log it's action is dropped, and 5 minutes later 3 logs with action allowed. Why does it dropped then allowed it?


category: spyware

action: dropped

Threat Name: CobaltStrike.Gen Command and Control Traffic
Threat ID: 18005


L1 Bithead

I'm new to the forum, thanks in advance


Cyber Elite
Cyber Elite


Not sure if its the case here however logs are typically written at 'session end'. We would need to see redacted logs to try and figure this out. Just black out the source and destination IP's along with anything that could identify your company etc.


Hi, please find the ss below

FW logs blocked then allow.jpg

Cyber Elite
Cyber Elite


So the 'later' traffic is UDP (DNS-Base) so it has to 'time out' since there is no fin packets. This is the most likely reason for the later timestamp in the logs. The policy is most likely set to log at session end, which is best practice.


Hope this helps.

does UDP has fin packets?

i did a bit of research from your explanation, using the first link below to understand the session end. then using data from Session End reason: threat, i found out the answer in the second link. thanks for your help


Cyber Elite
Cyber Elite


Glad you found what you needed.



  • 7 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!