Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

The log is showing that the DNS request crossing the FW originates from your DNS server. 

This is usually the case when you have an infected machine in your internal network that is querying a malicious site or URL. The first DNS request is not crossing the FW, it goes from the infected machine to your internal DNS server, and then the DNS server is relaying that request to the Internet.

Unless you place your FW between your DNS server and your internal network segment, you won't be able to find the offender via the FW logs.

However, you might figure out the offender in the DNS server logs, if you have any.

View solution in original post

0 Kudos
(1)
Who rated this post