We have recently started to brick up our clients and servers with Endpoint Security Firewall, by using the application filter with/without digital signatures.
The odd thing is, why is there loads of blocked traffic on the dashboard that does not link to an application? Most of this is traffic only includes IP and port but no application id.
For an example there is some blocked outbound traffic that leads to some dropb** servers even tho we have allowed all dropb** applications.
I've checked both logs. Event monitor and debug.
But none of them carries the explanation why there is blocked traffic with no application linked to it.
Thanks for replying by the way.