logs generrated
samaj
Newbie ✭
My Sonicwall keep alerting me following logs of port scans, I know they happen all the time but why be alerted if there isn't anything to do about it.
Is there any thing i can do about it and trackback?
Security Services Alert Possible port scan detected
Security Services Alert Probable TCP FIN scan detected
Category: Entry Level Firewalls
0
Answers
Hi @samaj ,
You can track the log context and check if the Port scans are arriving on your WAN. Ignore, If the port scan from inside your network.
If the Logs are from the same WAN IP then either you can block the IP by using the access rule.
For Trackback you can disable the logging level for that event id and then enable the log automation so that the events will be sent via email and not showed up on the firewall UI. For Log automation, please check the KB below:
Thanks
Nevyaditha P
Technical Support Advisor, Premier Services