Stijn 0 Posted March 5, 2021 Share Posted March 5, 2021 Eset protect is generating tons of firewall alerts for our DMZ servers. The thing is, File Security does not have a firewall module so where are these alerts coming from? In addition, they are all legitimate traffic to the websites running on there so it's not even working properly. The alerts were not present in Eset Security Management Server 7.1 but popped up after upgrading to Eset Protect 8.0. Any have any suggestions? Link to comment Share on other sites More sharing options...
Administrators Marcos 4,931 Posted March 5, 2021 Administrators Share Posted March 5, 2021 Please provide a couple of records from the log. Are they logged in the Network protection log? Link to comment Share on other sites More sharing options...
Stijn 0 Posted March 5, 2021 Author Share Posted March 5, 2021 I cannot find that log between the others. Do I have to enable the Network protection advanced logging option on the servers? Link to comment Share on other sites More sharing options...
Administrators Marcos 4,931 Posted March 5, 2021 Administrators Share Posted March 5, 2021 What logs are you referring to? Could you please post a screen shot for clarification? Link to comment Share on other sites More sharing options...
Stijn 0 Posted March 8, 2021 Author Share Posted March 8, 2021 Here are the logs of one server. I left out the source and destination IP. Link to comment Share on other sites More sharing options...
Most Valued Members Nightowl 198 Posted March 8, 2021 Most Valued Members Share Posted March 8, 2021 35 minutes ago, Stijn said: Here are the logs of one server. I left out the source and destination IP. Your server is being attacked on ports 443 and 80 , probably as you have said it is DMZ so it's open to all the world. Link to comment Share on other sites More sharing options...
Stijn 0 Posted March 8, 2021 Author Share Posted March 8, 2021 Yeah those ports are open since it is hosting web services. So it might as well be legitimate traffic? Is there a way to tell Eset to keep blocking but no need to constantly go into alert? Link to comment Share on other sites More sharing options...
Most Valued Members Nightowl 198 Posted March 8, 2021 Most Valued Members Share Posted March 8, 2021 3 minutes ago, Stijn said: Yeah those ports are open since it is hosting web services. So it might as well be legitimate traffic? Is there a way to tell Eset to keep blocking but no need to constantly go into alert? In settings I can only find for displaying notifications not preventing it to send to management server I believe Let's wait for ESET Staff he can have more information than me. Link to comment Share on other sites More sharing options...
Recommended Posts