We are investigating a large number of blocked events. When I mouse over the source in Security Center > MX Events, it shows me the IP address, MAC address and OS info, with a link for View Client Details and a filter for Show this client only. The IP address shown is 10.20.28.21 port 47839, with mac address ending in 1c:7b. When I click on View client details, the client IP address is different - 10.20.18.47. Both these IPs are statically set, with the .21 address being a multifunction printer and the .47 addressing being a vulnerability management scanner appliance from our MSP. The mac address shown as associated with .21 is the correct mac for the device using the .47 address. Any idea why this might be showing up this way?
... View more