05-04-2018 06:59 PM - edited 02-21-2020 07:42 AM
i have infoblox dns and cisco firepower as edge FW but i have issue , when i see intrusion event in cisco firepower i found that the IP of infoblox dns is the top ip in event , i want to view the original Client IP before it goes to infoblox dns server ? to find the infected PC .
05-05-2018 10:30 AM
Hi , Could you please provide little more details about the setup?
If it's a proxy and you are talking about http request based intrusive events, you can enable original client is option in NAP policy.
If you are talking about intrusion event for dns request going to your dns server from internal machines,the event details would show the requester client ip address seen by firepower.
Hope it helps,
Yogesh
05-06-2018 04:34 AM
05-06-2018 01:35 PM
i seek help in view original client IP that requesting malware or botnet using dns tunneling , in my case when i see the intrusion list i found that infoblox dns server is the top of intrusion event and i can not find the original IP address .
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide