Firewall system log
I am new in pfsense and I am not sure if the log I am getting need attention. I don't remember from my previous log before that I saw that some IP address was successfully pass on our internal IP address for our mail server HTTPS 443. I just want to know if this log is normal if somebody from our organization log-in successfully on our webmal. what if somebody is trying to forcely login to our webmail that means they are allowed too?
Please see attached screenshot.
since theres a log of that it means that you have set up a rule to log all access to that ip,
the log is showing that somebody from OUTSIDE the firewall is accessing that server (hence the if =WAN)
comes back to: United States Charlottesville Embarq Corporation
Resolve Host: va-67-233-66-236.dhcp.embarqhsd.net