Hi @Timothy_Hall ,
yes, that is my doubt. a VPN traffic is initiated to check point from an unknown IP which is not configured in my device, traffic got rejected by the device but after that a response is sending as key install. details are in attached screen shot. what kind of behavior is this.
we are getting lot of request from this unknown IP to some of the internal IP's. service is IKE ( Screen shot attached). we don't have any DAIP for this setup. as a precautionary measure i have created an object and blocked this source IP in the policy.
is it a kind of attack. if yes how do i identity which device is originating this traffic and any helping hand from inside object.
Thank you for response.