Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sagar_Manandhar
Advisor
Jump to solution

bot prevention log meaning

hi,

What kind of bot event is this, where destination is its own default DNS trap default IP ? 

0 Kudos
1 Solution

Accepted Solutions
Benjamin_Hofst1
Participant

A Check Point Firewall saw a DNS Request namesvrtwo.serveftp.com. The Check Point Firewall answered the (suspicious) DNS Request with the default DNS Trap IP. If you have an internal DNS Server, the Firewall cannot see or log the original Requester (the Client with a possible Bot) because the DNS Request comes form the internal DNS.

Then the client is sending a Request do namesvrtwo.serveftp.com (Resolved to the DNS Trap IP). This way you can find the Client infected by the Bot. 

View solution in original post

1 Reply
Benjamin_Hofst1
Participant

A Check Point Firewall saw a DNS Request namesvrtwo.serveftp.com. The Check Point Firewall answered the (suspicious) DNS Request with the default DNS Trap IP. If you have an internal DNS Server, the Firewall cannot see or log the original Requester (the Client with a possible Bot) because the DNS Request comes form the internal DNS.

Then the client is sending a Request do namesvrtwo.serveftp.com (Resolved to the DNS Trap IP). This way you can find the Client infected by the Bot. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events