cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
106
Views
0
Helpful
0
Replies

Client using an unusual port

dcanady55
Level 3
Level 3

Hello,

FTD's 2110 running 7.4.2. 

Under intrusion events dashboard some of my top attackers are my DC's that run DHCP and DNS. I'm trying to understand why Cisco is classifying what looks like normal DNS traffic as a port scan saying the client was using an unusual port. False positive or am I missing something? 

dcanady55_0-1741962032530.png

 

Thanks in advance. 

 

 

0 Replies 0