Attack from My Public IP

Fandi Kurnia Lv1Posted 22 Dec 2023 01:27

Hi,

We have a problem with the NGAF attack from our internal IP Public, which means internal IP Public Outgoing detect our internal IP Private.
How to now about the mac address and who from internal VM Linux attack from another url?

Thanks

Newbie517762 has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi,

Analyze the firewall logs for the public IP to find the attack's source IP.
Also, check the "Web Application Protection_Best Practice" link.
This attack protection includes application hiding, password protection, privilege control, data leak prevention, HTTP request anomaly detection, and scanner blocking.
Is this answer helpful?
Fandi Kurnia Lv1Posted 22 Dec 2023 12:11
  
Time: 20231222 09:22:18 Device(gateway ID:0E7867F4) detects WAF alert, Src IP:120.29.x.x  Dst IP:192.168.112.55 Attack type: Website scan Severity: Medium URL/Directory: example id/cgi-bin/ Port: 80 Description: Website-based attack is detected. Type:Website scan


120.29.x.x

MY TOPOLOY
CORE ROUTER -> SANGFOR NGAF (BRIDGE MODE) -> SANGFOR IAM (BRIDGE MODE) -> OUR CORE SWITCH

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders