Unknown Source and Unknown Destination IP address showing in monitor logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Unknown Source and Unknown Destination IP address showing in monitor logs

L1 Bithead

Hello Team,

 

Good day to you !!

 

++We have one customer he facing issue with Unknown Source and Unknown Destination IP address showing in monitor logs.

++That Unknown Source IP address traffic is showing in monitor traffic logs with unknown destination IP address which does not belongs to your organization
++as we can see that there are multiple unknown source IP address traffic with unknown destination IP address traffic in monitor logs with different different country name 
++most of the traffic are hitting to intrazone-default-rule.
 
Kindly help me to address the issue.
 
Regards
Sasikumari.
3 REPLIES 3

L2 Linker

It is really expected, since traffic coming from Internet to the public facing IP of the Firewall is traffic from untrust to untrust. It's advised to enable session logging on intrazone-zone and interzone policies only for troubleshooting reasons, since it might be filling your logs with information not really usefull.

In summary, it's the firewall doing its job 🙂 

Senior Network Security Engineer
PCNSE | CCNP | JNCIP

Hi @jfernandez1 

 

Is it really expected behavior as the Public facing ISP IP is different from what it is showing in traffic logs.

 

 Please find the attached screenshot for reference 

We don't know the source and Destination IP's .

PA.jpg

 

 

Thanks and Regards 

Satya Kalyan

Hello @Satyak 

 

yes, internet connections are continuously scanned from external actors, this since attackers may be taking multiple IP prefixes to scan and check if there's a service opened they can exploit, here's the importance of using firewalls 🙂 

Senior Network Security Engineer
PCNSE | CCNP | JNCIP
  • 1568 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!