I'm looking to track down an issue we're having with unknown rogue ip addresses reported by the Mcafee Rogue Detection System.
We are running only public addresses on our network yet we get rogue ip addresses. The report associates the "10.x.x.x address" to a sensor of one of our hosts with a public static address.
Thinking this is some kind of virus when we shut down the device the issue shows up on a second workstation on our network.
We've run virus scans and checked for virtual NICs, but can't figure out what is causing the activity. In addition to the private address we're also seeing one public address that doesn't belong to our network reported in a separate subnet.
Our boundary FW doesn't detect either of these IP address and they seem to be only reported by McAfee.
Any idea what this can be and how to deal with it?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.