Dear community,
We have the following issue and hope someone can help:
We have a huge network (over 200 Vlans) 50 cisco switches (incl. , 12 cisco core switches), 12 servers, 2 ASA 5550,and,.....
Our homepage is hosted by an external company and went down 2 days ago. The hosting company said that their server is being hit very often from inside our network, that’s why our external IP (which is our firewall IP) has been blocked, so we need to block cpanel ports for the outbound traffic (ports 2082,2085).
Is there any way to know which network or user is causing this, e.g. syslog in the ASAs ?
Many thanks