Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

Strange random connections dropped

$
0
0
Hy together

I'm not sure if its waf related. When I check the packet filter log of the firewall random connection attemps are made to the firewall interface itself, starting from ***.***.***.***:443 or 80 to a random port of the internal interface of the firewall (in dmz its the ip of the dmz interface). For sure no rule exists for that the packets will be dropped. I've tryed several things: disabled keep alive--> no success, excluded these servers from the outgoing proxy --> no change

It affects all virtualized servers protected with waf (Exchange 2013, 2x Ubuntu Apache)

Can somebody help me to solve this drops or explain why these are occouring?

thx!

Viewing all articles
Browse latest Browse all 14361

Trending Articles