- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-15-2024 02:30 AM
Hello Team,
Good day to you !!
++We have one customer he facing issue with Unknown Source and Unknown Destination IP address showing in monitor logs.
05-15-2024 02:39 PM
It is really expected, since traffic coming from Internet to the public facing IP of the Firewall is traffic from untrust to untrust. It's advised to enable session logging on intrazone-zone and interzone policies only for troubleshooting reasons, since it might be filling your logs with information not really usefull.
In summary, it's the firewall doing its job 🙂
05-18-2024 03:48 AM
Hi @jfernandez1
Is it really expected behavior as the Public facing ISP IP is different from what it is showing in traffic logs.
Please find the attached screenshot for reference
We don't know the source and Destination IP's .
Thanks and Regards
Satya Kalyan
05-20-2024 06:18 AM
Hello @Satyak
yes, internet connections are continuously scanned from external actors, this since attackers may be taking multiple IP prefixes to scan and check if there's a service opened they can exploit, here's the importance of using firewalls 🙂
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!