- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2015 03:40 AM - edited 03-11-2019 11:32 PM
I have been informed by my ISP that a botnet has been detected and the ip address is the Global PAT address. how do i trace the source ip?
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2015 05:29 AM
Probably it's not possible any more. What do you need:
- An exact timestamp from the event and if possible the destination-address/port.
- Your firewall-log showing which PC was communicating at that moment with the destination.
- If you are using DHCP, you also need a DHCP-log to see which internal system was using that IP at that time.
Perhaps it's time to migrate to ASA with FirePOWER.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2015 05:29 AM
Probably it's not possible any more. What do you need:
- An exact timestamp from the event and if possible the destination-address/port.
- Your firewall-log showing which PC was communicating at that moment with the destination.
- If you are using DHCP, you also need a DHCP-log to see which internal system was using that IP at that time.
Perhaps it's time to migrate to ASA with FirePOWER.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2015 07:59 AM
Thanks Karsten
I'll put that on my Christmas wish list :-)
