- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: bot prevention log meaning
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
bot prevention log meaning
hi,
What kind of bot event is this, where destination is its own default DNS trap default IP ?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A Check Point Firewall saw a DNS Request namesvrtwo.serveftp.com. The Check Point Firewall answered the (suspicious) DNS Request with the default DNS Trap IP. If you have an internal DNS Server, the Firewall cannot see or log the original Requester (the Client with a possible Bot) because the DNS Request comes form the internal DNS.
Then the client is sending a Request do namesvrtwo.serveftp.com (Resolved to the DNS Trap IP). This way you can find the Client infected by the Bot.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A Check Point Firewall saw a DNS Request namesvrtwo.serveftp.com. The Check Point Firewall answered the (suspicious) DNS Request with the default DNS Trap IP. If you have an internal DNS Server, the Firewall cannot see or log the original Requester (the Client with a possible Bot) because the DNS Request comes form the internal DNS.
Then the client is sending a Request do namesvrtwo.serveftp.com (Resolved to the DNS Trap IP). This way you can find the Client infected by the Bot.
