cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
775
Views
0
Helpful
3
Replies

how to know original ip requested domain/URL ??

elbeshti
Level 1
Level 1

i have infoblox dns and cisco firepower as edge FW but i have issue , when i see intrusion event in cisco firepower i found that the IP of infoblox dns is the top ip in event , i want to view the original Client IP before it goes to infoblox dns server ? to find the infected PC .

3 Replies 3

yogdhanu
Cisco Employee
Cisco Employee

Hi , Could you please provide little more details about the setup?

If it's a proxy and you are talking about http request based intrusive events, you can enable original client is option in NAP policy.

If you are talking about intrusion event for dns request going to your dns server from internal machines,the event details would show the requester client ip address seen by firepower.

 

Hope it helps,

Yogesh

Thank you for your replay but I need the following :

If you are talking about intrusion event for dns request going to your dns server from internal machines,the event details would show the requester client ip address seen by firepower.


i seek help in view original client IP that requesting malware or botnet using dns tunneling , in my case when i see the intrusion list i found that infoblox dns server is the top of intrusion event and i can not find the original IP address .

 
 
Review Cisco Networking for a $25 gift card