08-21-2024 06:55 AM
I got alerts from my Firepower this morning for this. The source IP is my DNS server, and the destination was my DNS provider. I can't find anything in the alert that I can use to locate the system that actually issued the request to my DNS server. I'm guessing it was a website/domain being requested that triggered it, but how do I find out what that was. If I had that, I could then check my logs for which system requested it.
08-21-2024 08:25 AM
You wouldn't see it based on the DNS query itself since that traffic was only between the internal and public DNS resolver from the firewall's perspective.
However, you might be able to find the subsequent connection that would normally follow the end host having received an IP to match the FQDN. Search for that destination IP in your connection events (assuming you haven't rolled over the database records and you are logging all connections).
08-21-2024 08:32 AM
Try
Show dns
Show run dns
Show fqdn
I am not so sure you will get url request but try, then add this url to specific ACP and detect how try connect this url
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide