FireGen Report
| Info | Value |
|---|---|
| Log profile | Log profile Netscreen |
| Analyzed log(s) |
F:\Logs\SGS\logfile.txt.20060321 (151.00 MB) |
| Firewall type | SGS |
| Analysis interval | All entries in the specified log |
Firewalls
| No | Firewall | Connections | Traffic (MB) | Denials | Warnings | URLs | 1 | fw.celotexfiberboard.com | 239,352 | 2,422.59 | 33,875 | 1,384 | 00 |
|---|
Message types
| No | Code | Message sample | Count | 2 | 101 | Time reset, Type=step, Offset=-0.142220 | 05 | 3 | 107 | Closing log file | 01 | 4 | 108 | Starting new log file, UTC offset used, Offset=-0600 | 01 | 5 | 109 | Re-reading configuration file, Information=Bad Services traffic saturation alert threshold set to: 20.00 % | 34 | 6 | 115 | Successful authentication from remote management client, User=jolson, Source IP=192.168.1.131, Source Name=192.168.1.131, Destination IP=192.168.1.253, Destination Port=2456 | 11 | 7 | 116 | Remote management completed, User=jolson, Source IP=192.168.1.131, Source Name=192.168.1.131, Destination IP=192.168.1.253, Destination Port=2456 | 10 | 8 | 117 | Daemon starting, Program Name=rtspd, Operation=Initialize, Resource=rtspd, Status=Success, State=Starting | 28 | 9 | 118 | Daemon exiting, Program Name=GWControl Service, Operation=Validate, Resource=signal(15), Status=Success, State=OK | 01 | 10 | 120 | Not sending ICMP Unreachable in response to non-informational ICMP received on interface, Source IP=68.50.76.167, Destination IP=65.5.124.15, IP Code=ICMP, IP Code=Unreachable (port), String Value=Inner Packet data follows, Source IP=65.5.124.15, Destination IP=68.50.76.167, IP Code=UDP, Source Port=11245, Destination Port=1026, Adapter=eth2 | 2,188 | 11 | 121 | Statistics, Duration=1.31 , Authentication Result=N/A, ID=dDzAt, Sent=95, Received=334, Bytes=429, Source Interface=eth1, Source IP=64.18.0.230, Source Port=41170, Source Name=64.18.0.230, Client Destination=66.155.139.150, Client Port=25, Server Source=192.168.1.253, Server Source Port=60916, Destination Interface=eth0, Destination IP=192.168.1.3, Destination Port=25, Destination Name=192.168.1.3, Operation=N/A, Protocol=25/tcp, Rule ID=1 | 239,352 | 12 | 122 | Daemon listening on port(s), Program Name=User Library, Operation=Initialize, Resource= 80/tcp, 443/tcp, Status=Success, State=OK | 58 | 13 | 124 | Parameters and filters set for interfaces, Setting=eth2, Operation=Modify, Revision=0 | 18 | 14 | 131 | Remote management connection request, From=192.168.1.179, To=192.168.1.253, Source Port=4247, Destination Port=423 | 05 | 15 | 152 | LiveUpdate found files up-to-date, Program Name=IDS, Operation=Live Update, Resource=Intrusion Detection and Prevention Subscription Update, Status=Success, State=OK | 72 | 16 | 164 | Received command to reload filter configuration, Operation=Modify, Revision=0 | 06 | 17 | 170 | IDS: Open called on device ids | 17 | 18 | 190 | HTTP_BAD_REQURL6_0, Title= HTTP Malformed URL, Policy Tag= SUSPICIOUS_HTTP, Vendor=SYMC, Class=sniffer, Family=integrity, Context Data=UkVHSVNURVIgc2lwOjY4LjE0Mi4yMzMuMTc5OjgwO3RyYW5zcG9ydD10Y3AgU0lQLzIuMA, Context Description=HTTP Request, Flow Cookie=TCP%EXACT%10.35.94.136:1029/68.142.233.179:80#255, IP Protocol=TCP, Level=32, Reliability=128, Payload=UkVHSVNURVIgc2lwOjY4LjE0Mi4yMzMuMTc5OjgwO3RyYW5zcG9ydD10Y3AgU0lQLzIuMA0KRnJvbTogPHNpcDpqYXNvbl9zY2huYWJsZWdnZXIyMDAxQDY4LjE0Mi4yMzMuMTc5OjgwPjt0YWc9ODM2MWNlOC0wLTEzYmItNWU, Payload left offset=52, Payload right offset=53, Start time=Mar 21, 2006 21:17:06, End Time=Mar 21, 2006 21:17:06, Source IP=10.35.94.136, Source Port=1029, Destination IP=68.142.233.179, Destination Port=80, Packet=RQACE+6nQAB+BnVQCiNeiESO6bMEBQBQ+R+dZaaNKkpQGP//QAgAAA, Interface=ids, Interface ID=232, Alert Source MAC addr=00:50:80:04:9d:81, Alert Destination MAC addr=00:00:00:00:00:00, VLAN ID=0, Outcome=unknown | 152 | 19 | 201 | Repeated, Consolidated Message=232 NOTICE: Sending ICMP unreachable, Count=2, IP Code=Unreachable (host prohibited), Source IP=12.119.118.26, Destination IP=135.89.152.51, IP Code=ICMP, IP Subtype ID=26040, IP Code=Echo reply, Adapter=eth2 | 66 | 20 | 216 | Access denied, Protocol=GWControl Service, Operation=Validate, Destination Name=216.52.1.1, Source Name=10.35.93.74, Status=Failure, State=Fail, Source IP=0.0.0.0, Rule= [default rule] [no rules found], PID=-2145566761, Service=123/udp | 29,719 | 21 | 219 | Cannot parse URL, Program Name=httpd, Operation=Validate, Resource=OPTIONS / HTTP/1.1\r\ntranslate: f\r\nUser-Agent: Microsoft-WebDAV-MiniRedir/5.1.2600\r\nHost: 66.155.139.150\r\nContent-Length: 0\r\nConnection: Keep-Alive\r\n\r\n, Status=Failure, State=Fail | 48 | 22 | 226 | IP packet dropped due to bad source address, Source IP=127.0.0.1, Destination IP=192.168.1.10, IP Code=ICMP, IP Subtype ID=1234, IP Code=Echo request, Adapter=eth2 | 02 | 23 | 227 | VPN packet dropped because the packet is either too old or has been received before by tunnel (potential replay attack), Source IP=204.183.33.108, Destination IP=66.155.139.158, IP Code=UDP, Source Port=56092, Destination Port=786, Tunnel=3.isakmp.30@204.183.33.108 | 29 | 24 | 228 | Cannot connect to port, Program Name=httpd, Operation=Connect, Resource=63.208.226.225, Status=[110] Connection tim, State=Fail, Protocol=http, Host=63.208.226.225, Destination Port=80, IP Address=63.208.226.225 | 529 | 25 | 229 | IP packet dropped, String Value=TCP Reset, Source IP=65.5.152.162, Destination IP=65.5.124.20, Source Port=37214, Destination Port=135 | 4,101 | 26 | 230 | Not authorized, Protocol=TCP GSP, Source IP=69.18.47.238, Source Port=2827, Source Name=69.18.47.238 | 25 | 27 | 232 | Sending ICMP unreachable, String Value=host unreachable, Source IP=10.35.93.74, Destination IP=216.52.1.1, Source Port=2054, Destination Port=123 | 16,629 | 28 | 238 | User proxy by means of outside interface is not allowed, use httpd.allow_external_proxy to change it, Program Name=httpd, Operation=Connect, Status=Failure, State=Denying, User=63.229.225.195, Interface=eth1 | 54 | 29 | 239 | Sending TCP reset not allowed, Source IP=10.35.93.106, Destination IP=192.168.1.3, IP Code=TCP, Flag=SYN, Source Port=2082, Destination Port=135, Adapter=eth2 | 3,256 | 30 | 240 | TCP packet dropped due to bad TCP flags combination, Source IP=88.136.165.218, Destination IP=65.5.124.4, IP Code=TCP, Flag=FIN, Source Port=51679, Destination Port=60729, Adapter=eth2, Probable Probe=QueSO, Flag=0x01 | 03 | 31 | 271 | Temporarily suppressing messages because the security gateway has reached log limits for driver messages at this level, Count=200, Interval=seconds | 03 | 32 | 290 | MSSQL_STACKOVERFLOW, Title= MSSQL StackOverflow, CVE= CAN-2002-0649, Policy Tag= CUSTOM_SQL, Vendor=SYMC, Class=sniffer, Family=integrity, Flow Cookie=UDP%EXACT,SPOOF%58.1.104.113:1085/66.155.139.155:1434#255, IP Protocol=UDP, Level=150, Reliability=128, Payload left offset=0, Payload right offset=0, Start time=Mar 21, 2006 23:57:28, End Time=Mar 21, 2006 23:57:28, Source IP=58.1.104.113, Source Port=1085, Destination IP=66.155.139.155, Destination Port=1434, Packet=RQABlBtQAABtEcBgOgFocUKbi5sEPQWaAYDAZQ, Interface=ids, Interface ID=232, Alert Source MAC addr=00:04:dd:08:a4:42, Alert Destination MAC addr=00:00:00:00:00:00, VLAN ID=0, Outcome=unknown | 1,209 | 33 | 301 | Repeated:, Consolidated Message=343 WARNING: Packet for interface was routed to interface, Count=2, Source IP=10.254.254.1, Destination IP=12.119.118.26, IP Code=ICMP, IP Code=Unreachable (host prohibited), String Value=Inner Packet data follows, Source IP=12.119.118.26, Destination IP=135.89.152.51, IP Code=ICMP, IP Subtype ID=26040, IP Code=Echo reply, Adapter=eth2, IP Address=66.155.139.158 | 100 | 34 | 334 | Denied access to command, Count=1, Source Name=83.110.176.142, Source IP=2.0.13.121, Destination Name=66.155.139.150, Destination IP=2.0.0.139, Source Interface=66.155.139.158 | 29 | 35 | 335 | VPN packet dropped because VPN is not enabled, Source IP=69.222.255.63, Destination IP=66.155.139.158, Payload=0xb22f3b85 | 121 | 36 | 343 | Using rule ID 8 because two equally good rules were found. Rule 5 = Rule 8, Program Name=GWControl Service, Operation=Validate, Status=Success, State=OK | 2,187 | 37 | 344 | Non-transparent call, Source Name=220.135.254.38, Source IP=220.135.254.38, Destination Name=fw.celotexfiberboard.com, Destination IP=66.155.139.158 | 12 | 38 | 347 | Possible port scan detected, Adapter=eth2, Source IP=222.73.4.156, Destination IP=65.5.124.24, IP Code=TCP, Flag=SYN, Flag=ACK, Source Port=7000, Destination Port=503 | 55 | 39 | 370 | NET: 5 messages suppressed. | 01 | 40 | 401 | Remote management login failed, User=jolson, Source IP=192.168.1.131, Source Name=192.168.1.131, Destination IP=192.168.1.253, Destination Port=2456 | 02 | 41 | 452 | LiveUpdate failed, Program Name=Content Filtering, Operation=Live Update, Resource=Content Filtering URL Update, Status=Failure, State=Fail | 02 | 42 | 456 | HTTPS service not supported, Program Name=httpd, Operation=Connect, Resource=192.168.1.3, Status=Failure, State=Abort | 146 | 43 | 590 | COUNTER_UNACKED_SYNS_HIGH, Title= SYN flood, CVE= CVE-1999-0116, Policy Tag= DOS_FLOODS, Vendor=SYMC, Class=sniffer, Family=availability, Flow Cookie=TCP%COUNTER,SPOOF,SYNS%10.35.94.136:4497/204.15.225.163:80#512, IP Protocol=TCP, Level=-3, Reliability=128, Payload left offset=0, Payload right offset=0, Start time=Mar 21, 2006 16:48:59, End Time=Mar 21, 2006 16:48:59, Source IP=10.35.94.136, Source Port=4497, Destination IP=204.15.225.163, Destination Port=80, Interface=ids, Interface ID=232, Alert Source MAC addr=00:50:80:04:9d:81, Alert Destination MAC addr=00:00:00:00:00:00, VLAN ID=0, Outcome=unknown | 23 |
|---|
Firewall: fw.celotexfiberboard.com
fw.celotexfiberboard.com - Traffic and denials per hour




| Hour | Traffic (MB) | % | Connections | % | Denials | % | |
|---|---|---|---|---|---|---|---|
| 00-01 | 12.00 | 0.51 | 3,228 | 1.18 | 1,084 | 3.20 | |
| 01-02 | 10.00 | 0.43 | 2,834 | 1.04 | 883 | 2.61 | |
| 02-03 | 29.00 | 1.21 | 4,366 | 1.60 | 1,153 | 3.40 | |
| 03-04 | 17.00 | 0.71 | 2,161 | 0.79 | 930 | 2.75 | !!! |
| 04-05 | 14.00 | 0.58 | 3,970 | 1.45 | 1,181 | 3.49 | |
| 05-06 | 108.00 | 4.49 | 10,485 | 3.84 | 1,001 | 2.95 | |
| 06-07 | 59.00 | 2.47 | 8,009 | 2.93 | 1,281 | 3.78 | |
| 07-08 | 130.00 | 5.37 | 20,742 | 7.59 | 1,115 | 3.29 | |
| 08-09 | 167.00 | 6.93 | 21,117 | 7.73 | 2,086 | 6.16 | |
| 09-10 | 141.00 | 5.84 | 19,236 | 7.04 | 1,863 | 5.50 | |
| 10-11 | 157.00 | 6.48 | 23,121 | 8.46 | 2,198 | 6.49 | |
| 11-12 | 216.00 | 8.93 | 22,909 | 8.38 | 1,875 | 5.54 | |
| 12-13 | 168.00 | 6.97 | 20,933 | 7.66 | 1,920 | 5.67 | |
| 13-14 | 282.00 | 11.68 | 23,560 | 8.62 | 1,746 | 5.15 | |
| 14-15 | 226.00 | 9.35 | 21,442 | 7.85 | 2,007 | 5.92 | |
| 15-16 | 265.00 | 10.95 | 13,866 | 5.07 | 1,723 | 5.09 | |
| 16-17 | 131.00 | 5.41 | 15,364 | 5.62 | 1,929 | 5.69 | |
| 17-18 | 65.00 | 2.72 | 9,167 | 3.36 | 1,591 | 4.70 | |
| 18-19 | 69.00 | 2.86 | 7,711 | 2.82 | 1,140 | 3.37 | |
| 19-20 | 30.00 | 1.27 | 5,712 | 2.09 | 1,151 | 3.40 | |
| 20-21 | 74.00 | 3.07 | 3,438 | 1.26 | 950 | 2.80 | |
| 21-22 | 09.00 | 0.39 | 2,976 | 1.09 | 1,113 | 3.29 | !!! |
| 22-23 | 23.00 | 0.95 | 3,124 | 1.14 | 847 | 2.50 | |
| 23-24 | 09.00 | 0.40 | 3,756 | 1.37 | 1,108 | 3.27 |
fw.celotexfiberboard.com - Interfaces
| No | Interfaces | Connections | MB | % | Denials | Warnings |
|---|---|---|---|---|---|---|
| 1 | eth0 | 336 | 12.44 | 00.51 | 00 | 00 |
| 2 | eth0 to eth1 | 41,175 | 665.40 | 27.47 | 00 | 00 |
| 3 | eth0 to eth2 | 22 | 00.00 | 00.00 | 00 | 00 |
| 4 | eth0 to N/A | 10 | 00.02 | 00.00 | 00 | 00 |
| 5 | eth1 to eth0 | 13,436 | 245.08 | 10.12 | 00 | 00 |
| 6 | eth1 | 604 | 00.00 | 00.00 | 00 | 00 |
| 7 | eth1 to N/A | 13 | 00.01 | 00.00 | 00 | 00 |
| 8 | eth2 to eth0 | 309 | 16.83 | 00.69 | 00 | 00 |
| 9 | eth2 to eth1 | 182,905 | 1,334.25 | 55.08 | 00 | 00 |
| 10 | eth2 to N/A | 01 | 11.05 | 00.46 | 00 | 00 |
| 11 | N/A to eth0 | 21 | 00.01 | 00.00 | 00 | 00 |
| 12 | N/A | 520 | 137.49 | 05.68 | 00 | 00 |
| 13 | eth2 | 00 | 00.00 | 00.00 | 55 | 00 |
| 14 | Not specified | 00 | 00.00 | 00.00 | 33,820 | 1,384 |
| Total | 239,352 | 2,422.59 | 33,875 | 1,384 |
Firewall: fw.celotexfiberboard.com - Interface: eth0 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.3 | 10,331,771 | 79.18 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.144 | 1,212,411 | 9.29 | |
| 3 | 192.168.1.73 | 633,824 | 4.86 | |
| 4 | 192.168.1.179 | 365,258 | 2.80 | |
| 5 | 192.168.1.141 | 291,912 | 2.24 | |
| 6 | 192.168.1.138 | 116,054 | 0.89 | |
| 7 | 192.168.1.153 | 94,932 | 0.73 | |
| 8 | 192.168.1.145 | 2,456 | 0.02 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.3 | 11,062,983 | 84.78 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.205 | 1,985,635 | 15.22 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.1.3 | HTTP-HTTPS | 34 | 10,331,771 | 79.18 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.144 | HTTP | 147 | 1,212,411 | 9.29 | |
| 3 | 192.168.1.73 | HTTP-HTTPS | 15 | 633,824 | 4.86 | |
| 4 | 192.168.1.179 | HTTP | 34 | 365,258 | 2.80 | |
| 5 | 192.168.1.141 | HTTP | 86 | 291,912 | 2.24 | |
| 6 | 192.168.1.138 | HTTP | 14 | 116,054 | 0.89 | |
| 7 | 192.168.1.153 | HTTP-HTTPS | 03 | 93,750 | 0.72 | |
| 8 | 192.168.1.145 | HTTP-HTTPS | 01 | 1,474 | 0.01 | |
| 9 | 192.168.1.153 | HTTP | 01 | 1,182 | 0.01 | |
| 10 | 192.168.1.145 | HTTP | 01 | 982 | 0.01 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.1.3 | 192.168.1.3 | HTTP-HTTPS | 34 | 10,331,771 | 79.18 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.144 | 192.168.1.205 | HTTP | 147 | 1,212,411 | 9.29 | |
| 3 | 192.168.1.73 | 192.168.1.3 | HTTP-HTTPS | 15 | 633,824 | 4.86 | |
| 4 | 192.168.1.179 | 192.168.1.205 | HTTP | 34 | 365,258 | 2.80 | |
| 5 | 192.168.1.141 | 192.168.1.205 | HTTP | 86 | 291,912 | 2.24 | |
| 6 | 192.168.1.138 | 192.168.1.205 | HTTP | 14 | 116,054 | 0.89 | |
| 7 | 192.168.1.153 | 192.168.1.3 | HTTP-HTTPS | 03 | 93,750 | 0.72 | |
| 8 | 192.168.1.145 | 192.168.1.3 | HTTP-HTTPS | 01 | 1,474 | 0.01 | |
| 9 | 192.168.1.153 | 192.168.1.3 | HTTP | 01 | 1,182 | 0.01 | |
| 10 | 192.168.1.145 | 192.168.1.3 | HTTP | 01 | 982 | 0.01 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP-HTTPS | 53 | 11,060,819 | 84.77 | |
| 2 | HTTP | 283 | 1,987,799 | 15.23 |

Firewall: fw.celotexfiberboard.com - Interfaces: eth0 to eth1 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.3 | 203,860,340 | 29.22 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.139 | 170,960,013 | 24.50 | |
| 3 | 192.168.1.179 | 67,000,974 | 9.60 | |
| 4 | 192.168.1.190 | 58,090,350 | 8.33 | |
| 5 | 192.168.1.173 | 30,625,577 | 4.39 | |
| 6 | 192.168.1.144 | 26,343,766 | 3.78 | |
| 7 | 192.168.1.138 | 26,175,046 | 3.75 | |
| 8 | 192.168.1.145 | 25,995,170 | 3.73 | |
| 9 | 192.168.1.132 | 23,400,641 | 3.35 | |
| 10 | 192.168.1.182 | 13,017,343 | 1.87 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | cds301.ord.llnw.net (68.142.72.171) | 84,441,308 | 12.10 | |
| 2 | cds302.ord.llnw.net (68.142.72.172) | 54,888,464 | 7.87 | |
| 3 | hrpayroll-ml.ceridian.com (170.153.222.25) | 47,442,421 | 6.80 | |
| 4 | bda-216-9-250-181.bis3.ap.blackberry.com (216.9.250.181) | 42,813,172 | 6.14 | |
| 5 | zeus.lunarpages.com (216.193.211.2) | 25,777,036 | 3.69 | |
| 6 | mx03.bis.na.blackberry.com (216.9.248.34) | 17,919,851 | 2.57 | |
| 7 | mx01.bis.na.blackberry.com (216.9.248.32) | 14,262,765 | 2.04 | |
| 8 | 63-246-140-18.static.sagonet.net (63.246.140.18) | 13,143,748 | 1.88 | |
| 9 | mx04.bis.na.blackberry.com (216.9.248.35) | 12,238,332 | 1.75 | |
| 10 | host151.2000greetings.com (199.218.5.151) | 8,564,511 | 1.23 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.1.3 | TCP/25 - smtp | 1,665 | 202,617,428 | 29.04 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.139 | HTTP | 5,025 | 166,832,585 | 23.91 | |
| 3 | 192.168.1.190 | HTTP-HTTPS | 1,891 | 51,376,265 | 7.36 | |
| 4 | 192.168.1.173 | HTTP | 2,933 | 29,631,274 | 4.25 | |
| 5 | 192.168.1.145 | HTTP | 1,656 | 25,221,835 | 3.61 | |
| 6 | 192.168.1.138 | HTTP | 3,030 | 24,988,002 | 3.58 | |
| 7 | 192.168.1.144 | HTTP | 2,409 | 23,515,678 | 3.37 | |
| 8 | 192.168.1.132 | HTTP | 1,950 | 23,144,641 | 3.32 | |
| 9 | 192.168.1.179 | HTTP | 1,636 | 20,376,311 | 2.92 | |
| 10 | 192.168.1.131 | HTTP | 716 | 11,225,116 | 1.61 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.1.139 | cds301.ord.llnw.net (68.142.72.171) | HTTP | 05 | 84,440,937 | 12.10 | |
| 2 | 192.168.1.139 | cds302.ord.llnw.net (68.142.72.172) | HTTP | 04 | 54,888,464 | 7.87 | |
| 3 | 192.168.1.190 | hrpayroll-ml.ceridian.com (170.153.222.25) | HTTP-HTTPS | 990 | 47,442,421 | 6.80 | |
| 4 | 192.168.1.3 | bda-216-9-250-181.bis3.ap.blackberry.com (216.9.250.181) | TCP/25 - smtp | 18 | 42,813,172 | 6.14 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 5 | 192.168.1.3 | mx03.bis.na.blackberry.com (216.9.248.34) | TCP/25 - smtp | 105 | 17,919,851 | 2.57 | |
| 6 | 192.168.1.3 | zeus.lunarpages.com (216.193.211.2) | TCP/25 - smtp | 04 | 16,059,204 | 2.30 | |
| 7 | 192.168.1.3 | mx01.bis.na.blackberry.com (216.9.248.32) | TCP/25 - smtp | 109 | 14,262,765 | 2.04 | |
| 8 | 192.168.1.3 | mx04.bis.na.blackberry.com (216.9.248.35) | TCP/25 - smtp | 94 | 12,238,332 | 1.75 | |
| 9 | 192.168.1.179 | zeus.lunarpages.com (216.193.211.2) | HTTP | 60 | 9,717,832 | 1.39 | |
| 10 | 192.168.1.132 | host151.2000greetings.com (199.218.5.151) | HTTP | 45 | 8,564,511 | 1.23 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP | 27,740 | 366,377,690 | 52.51 | |
| 2 | TCP/25 - smtp | 1,690 | 202,668,250 | 29.05 | |
| 3 | HTTP-HTTPS | 4,225 | 80,375,521 | 11.52 | |
| 4 | TCP/1214 - kazaa | 08 | 9,355,003 | 1.34 | |
| 5 | TCP/4524 | 02 | 7,090,199 | 1.02 | |
| 6 | UDP/53 - dns | 837 | 6,534,943 | 0.94 | |
| 7 | TCP/2463 | 02 | 5,306,526 | 0.76 | |
| 8 | TCP/3694 | 01 | 4,946,701 | 0.71 | |
| 9 | TCP/3932 | 01 | 2,660,242 | 0.38 | |
| 10 | TCP/1521 - oracle | 02 | 2,270,032 | 0.33 |

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 192.168.1.3 | bda-216-9-250-181.bis3.ap.blackberry.com (216.9.250.181) | 18 | 42,813,172 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.3 | mx03.bis.na.blackberry.com (216.9.248.34) | 105 | 17,919,851 | |
| 3 | 192.168.1.3 | zeus.lunarpages.com (216.193.211.2) | 04 | 16,059,204 | |
| 4 | 192.168.1.3 | mx01.bis.na.blackberry.com (216.9.248.32) | 109 | 14,262,765 | |
| 5 | 192.168.1.3 | mx04.bis.na.blackberry.com (216.9.248.35) | 94 | 12,238,332 | |
| 6 | 192.168.1.3 | mx02.bis.na.blackberry.com (216.9.248.33) | 104 | 7,390,442 | |
| 7 | 192.168.1.3 | bda-216-9-250-163.bis3.ap.blackberry.com (216.9.250.163) | 21 | 6,347,192 | |
| 8 | 192.168.1.3 | mx01.birch.net (216.212.0.63) | 02 | 4,790,768 | |
| 9 | 192.168.1.3 | bda-216-9-250-168.bis3.ap.blackberry.com (216.9.250.168) | 29 | 3,289,441 | |
| 10 | 192.168.1.3 | bda-216-9-250-177.bis3.ap.blackberry.com (216.9.250.177) | 22 | 3,244,345 |
Firewall: fw.celotexfiberboard.com - Interfaces: eth0 to eth2 - Go to top
Top 10 sources
Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.3 | 352 | 100.00 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.80.80.75 | 112 | 31.82 | 23 denials recorded on 3/21/2006 9:36:42 AM |
| 2 | 10.0.0.58 | 32 | 9.09 | |
| 3 | 10.35.94.136 | 32 | 9.09 | |
| 4 | 10.35.94.139 | 32 | 9.09 | |
| 5 | 10.35.94.112 | 32 | 9.09 | |
| 6 | 10.0.0.77 | 32 | 9.09 | |
| 7 | 10.35.94.121 | 32 | 9.09 | |
| 8 | 10.35.93.103 | 32 | 9.09 | |
| 9 | 192.168.0.176 | 16 | 4.55 | 7 denials recorded on 3/21/2006 9:36:42 AM |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.1.3 | UDP/4143 | 03 | 48 | 13.64 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.3 | UDP/1126 | 02 | 32 | 9.09 | |
| 3 | 192.168.1.3 | UDP/4774 | 02 | 32 | 9.09 | |
| 4 | 192.168.1.3 | UDP/2740 | 02 | 32 | 9.09 | |
| 5 | 192.168.1.3 | UDP/1091 | 02 | 32 | 9.09 | |
| 6 | 192.168.1.3 | UDP/1130 | 02 | 32 | 9.09 | |
| 7 | 192.168.1.3 | UDP/1244 | 02 | 32 | 9.09 | |
| 8 | 192.168.1.3 | UDP/3156 | 02 | 32 | 9.09 | |
| 9 | 192.168.1.3 | UDP/4271 | 02 | 32 | 9.09 | |
| 10 | 192.168.1.3 | UDP/3357 | 02 | 32 | 9.09 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.1.3 | 10.80.80.75 | UDP/4143 | 03 | 48 | 13.64 | 23 denials recorded on 3/21/2006 9:36:42 AM 23 denials recorded on 3/21/2006 9:36:42 AM 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.3 | 10.0.0.58 | UDP/1126 | 02 | 32 | 9.09 | |
| 3 | 192.168.1.3 | 10.35.94.136 | UDP/4774 | 02 | 32 | 9.09 | |
| 4 | 192.168.1.3 | 10.80.80.75 | UDP/2740 | 02 | 32 | 9.09 | |
| 5 | 192.168.1.3 | 10.35.94.139 | UDP/1091 | 02 | 32 | 9.09 | |
| 6 | 192.168.1.3 | 10.35.94.112 | UDP/1130 | 02 | 32 | 9.09 | |
| 7 | 192.168.1.3 | 10.0.0.77 | UDP/1244 | 02 | 32 | 9.09 | |
| 8 | 192.168.1.3 | 10.35.94.121 | UDP/3156 | 02 | 32 | 9.09 | |
| 9 | 192.168.1.3 | 10.80.80.75 | UDP/4271 | 02 | 32 | 9.09 | |
| 10 | 192.168.1.3 | 10.35.93.103 | UDP/3357 | 02 | 32 | 9.09 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/4143 | 03 | 48 | 13.64 | |
| 2 | UDP/1126 | 02 | 32 | 9.09 | |
| 3 | UDP/4774 | 02 | 32 | 9.09 | |
| 4 | UDP/2740 | 02 | 32 | 9.09 | |
| 5 | UDP/1091 | 02 | 32 | 9.09 | |
| 6 | UDP/1130 | 02 | 32 | 9.09 | |
| 7 | UDP/1244 | 02 | 32 | 9.09 | |
| 8 | UDP/3156 | 02 | 32 | 9.09 | |
| 9 | UDP/4271 | 02 | 32 | 9.09 | |
| 10 | UDP/3357 | 02 | 32 | 9.09 |

Firewall: fw.celotexfiberboard.com - Interfaces: eth0 to N/A - Go to top
Top 10 sources

Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.179 | 25,013 | 99.79 | |
| 2 | 192.168.1.136 | 52 | 0.21 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.253 | 25,065 | 100.00 |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.1.179 | SRL-3DES | 08 | 25,013 | 99.79 | |
| 2 | 192.168.1.136 | PING | 02 | 52 | 0.21 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.1.179 | 192.168.1.253 | SRL-3DES | 08 | 25,013 | 99.79 | |
| 2 | 192.168.1.136 | 192.168.1.253 | PING | 02 | 52 | 0.21 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | SRL-3DES | 08 | 25,013 | 99.79 | |
| 2 | PING | 02 | 52 | 0.21 |

Firewall: fw.celotexfiberboard.com - Interfaces: eth1 to eth0 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | exprod5mc109.postini.com (64.18.0.220) | 27,544,873 | 10.72 | |
| 2 | exprod5mx194.postini.com (64.18.0.40) | 8,594,474 | 3.34 | |
| 3 | exprod5mx195.postini.com (64.18.0.41) | 8,320,038 | 3.24 | |
| 4 | exprod5mx267.postini.com (64.18.0.90) | 5,665,655 | 2.20 | |
| 5 | 64.18.0.245 | 5,664,833 | 2.20 | |
| 6 | exprod5mx270.postini.com (64.18.0.93) | 5,273,483 | 2.05 | |
| 7 | exprod5mc111.postini.com (64.18.0.222) | 5,054,261 | 1.97 | |
| 8 | 64-142-91-60.dsl.static.sonic.net (64.142.91.60) | 5,041,991 | 1.96 | |
| 9 | exprod5ob105.obsmtp.com (64.18.0.179) | 4,993,828 | 1.94 | |
| 10 | 10.80.80.73 | 4,514,710 | 1.76 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.3 | 138,184,650 | 53.77 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.1.205 | 118,804,396 | 46.23 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | exprod5mc109.postini.com (64.18.0.220) | TCP/25 - smtp | 39 | 27,544,873 | 10.72 | |
| 2 | exprod5mx194.postini.com (64.18.0.40) | TCP/25 - smtp | 52 | 8,594,474 | 3.34 | |
| 3 | exprod5mx195.postini.com (64.18.0.41) | TCP/25 - smtp | 45 | 8,320,038 | 3.24 | |
| 4 | exprod5mx267.postini.com (64.18.0.90) | TCP/25 - smtp | 51 | 5,665,655 | 2.20 | |
| 5 | 64.18.0.245 | TCP/25 - smtp | 54 | 5,664,833 | 2.20 | |
| 6 | exprod5mx270.postini.com (64.18.0.93) | TCP/25 - smtp | 55 | 5,273,483 | 2.05 | |
| 7 | exprod5mc111.postini.com (64.18.0.222) | TCP/25 - smtp | 39 | 5,054,261 | 1.97 | |
| 8 | 64-142-91-60.dsl.static.sonic.net (64.142.91.60) | HTTP | 89 | 5,041,991 | 1.96 | |
| 9 | exprod5ob105.obsmtp.com (64.18.0.179) | TCP/25 - smtp | 44 | 4,993,828 | 1.94 | |
| 10 | 10.80.80.73 | HTTP-HTTPS | 444 | 4,510,136 | 1.75 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | exprod5mc109.postini.com (64.18.0.220) | 192.168.1.3 | TCP/25 - smtp | 39 | 27,544,873 | 10.72 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | exprod5mx194.postini.com (64.18.0.40) | 192.168.1.3 | TCP/25 - smtp | 52 | 8,594,474 | 3.34 | |
| 3 | exprod5mx195.postini.com (64.18.0.41) | 192.168.1.3 | TCP/25 - smtp | 45 | 8,320,038 | 3.24 | |
| 4 | exprod5mx267.postini.com (64.18.0.90) | 192.168.1.3 | TCP/25 - smtp | 51 | 5,665,655 | 2.20 | |
| 5 | 64.18.0.245 | 192.168.1.3 | TCP/25 - smtp | 54 | 5,664,833 | 2.20 | |
| 6 | exprod5mx270.postini.com (64.18.0.93) | 192.168.1.3 | TCP/25 - smtp | 55 | 5,273,483 | 2.05 | |
| 7 | exprod5mc111.postini.com (64.18.0.222) | 192.168.1.3 | TCP/25 - smtp | 39 | 5,054,261 | 1.97 | |
| 8 | 64-142-91-60.dsl.static.sonic.net (64.142.91.60) | 192.168.1.205 | HTTP | 89 | 5,041,991 | 1.96 | |
| 9 | exprod5ob105.obsmtp.com (64.18.0.179) | 192.168.1.3 | TCP/25 - smtp | 44 | 4,993,828 | 1.94 | |
| 10 | 10.80.80.73 | 192.168.1.3 | HTTP-HTTPS | 444 | 4,510,136 | 1.75 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP | 8,716 | 118,829,731 | 46.24 | |
| 2 | TCP/25 - smtp | 2,512 | 111,221,449 | 43.28 | |
| 3 | HTTP-HTTPS | 2,208 | 26,937,866 | 10.48 |

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | exprod5mc109.postini.com (64.18.0.220) | 192.168.1.3 | 39 | 27,544,873 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | exprod5mx194.postini.com (64.18.0.40) | 192.168.1.3 | 52 | 8,594,474 | |
| 3 | exprod5mx195.postini.com (64.18.0.41) | 192.168.1.3 | 45 | 8,320,038 | |
| 4 | exprod5mx267.postini.com (64.18.0.90) | 192.168.1.3 | 51 | 5,665,655 | |
| 5 | 64.18.0.245 | 192.168.1.3 | 54 | 5,664,833 | |
| 6 | exprod5mx270.postini.com (64.18.0.93) | 192.168.1.3 | 55 | 5,273,483 | |
| 7 | exprod5mc111.postini.com (64.18.0.222) | 192.168.1.3 | 39 | 5,054,261 | |
| 8 | exprod5ob105.obsmtp.com (64.18.0.179) | 192.168.1.3 | 44 | 4,993,828 | |
| 9 | exprod5mx268.postini.com (64.18.0.91) | 192.168.1.3 | 34 | 3,926,833 | |
| 10 | exprod5mc118.postini.com (64.18.0.230) | 192.168.1.3 | 51 | 2,902,927 |
Firewall: fw.celotexfiberboard.com - Interface: eth1 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | d463ce8c.datahighways.de (212.99.206.140) | 104 | 100.00 | |
| 2 | 59.14.163.5 | 00 | 0.00 | |
| 3 | VG-4-11.dialup.access.telecore.net.ru (213.135.64.160) | 00 | 0.00 | |
| 4 | 66-214-116-136.dhcp.hspr.ca.charter.com (66.214.116.136) | 00 | 0.00 | |
| 5 | 69-18-47-238.lisco.net (69.18.47.238) | 00 | 0.00 | |
| 6 | file.tnu.edu.tw (140.129.140.206) | 00 | 0.00 | |
| 7 | 204.16.208.119 | 00 | 0.00 | |
| 8 | 61.153.250.34 | 00 | 0.00 | |
| 9 | 218.232.109.197 | 00 | 0.00 | |
| 10 | 66.21.51.121 | 00 | 0.00 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 66.155.139.150 | 52 | 50.00 | |
| 2 | 66.155.139.155 | 52 | 50.00 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | d463ce8c.datahighways.de (212.99.206.140) | FTP | 02 | 104 | 100.00 | |
| 2 | 59.14.163.5 | TCP/7212 | 02 | 00 | 0.00 | |
| 3 | VG-4-11.dialup.access.telecore.net.ru (213.135.64.160) | TCP/25 - smtp | 01 | 00 | 0.00 | |
| 4 | 66-214-116-136.dhcp.hspr.ca.charter.com (66.214.116.136) | TCP/445 - netbios | 18 | 00 | 0.00 | |
| 5 | 69-18-47-238.lisco.net (69.18.47.238) | TCP/25 - smtp | 22 | 00 | 0.00 | |
| 6 | file.tnu.edu.tw (140.129.140.206) | UDP/1434 - ms sql monitor | 01 | 00 | 0.00 | |
| 7 | 204.16.208.119 | UDP/1027 - blaster-worm | 02 | 00 | 0.00 | |
| 8 | 61.153.250.34 | UDP/1434 - ms sql monitor | 01 | 00 | 0.00 | |
| 9 | 218.232.109.197 | TCP/7212 | 07 | 00 | 0.00 | |
| 10 | 66.21.51.121 | TCP/445 - netbios | 03 | 00 | 0.00 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | d463ce8c.datahighways.de (212.99.206.140) | 66.155.139.150 | FTP | 01 | 52 | 50.00 | |
| 2 | d463ce8c.datahighways.de (212.99.206.140) | 66.155.139.155 | FTP | 01 | 52 | 50.00 | |
| 3 | 59.14.163.5 | 66.155.139.150 | TCP/7212 | 01 | 00 | 0.00 | |
| 4 | 59.14.163.5 | 66.155.139.155 | TCP/7212 | 01 | 00 | 0.00 | |
| 5 | VG-4-11.dialup.access.telecore.net.ru (213.135.64.160) | 66.155.139.155 | TCP/25 - smtp | 01 | 00 | 0.00 | |
| 6 | 66-214-116-136.dhcp.hspr.ca.charter.com (66.214.116.136) | 66.155.139.150 | TCP/445 - netbios | 09 | 00 | 0.00 | |
| 7 | 66-214-116-136.dhcp.hspr.ca.charter.com (66.214.116.136) | 66.155.139.155 | TCP/445 - netbios | 09 | 00 | 0.00 | |
| 8 | 69-18-47-238.lisco.net (69.18.47.238) | 66.155.139.155 | TCP/25 - smtp | 22 | 00 | 0.00 | |
| 9 | file.tnu.edu.tw (140.129.140.206) | 66.155.139.155 | UDP/1434 - ms sql monitor | 01 | 00 | 0.00 | |
| 10 | 204.16.208.119 | 66.155.139.150 | UDP/1027 - blaster-worm | 01 | 00 | 0.00 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | FTP | 02 | 104 | 100.00 | |
| 2 | TCP/7212 | 14 | 00 | 0.00 | |
| 3 | TCP/25 - smtp | 23 | 00 | 0.00 | |
| 4 | TCP/445 - netbios | 160 | 00 | 0.00 | |
| 5 | UDP/1434 - ms sql monitor | 17 | 00 | 0.00 | |
| 6 | UDP/1027 - blaster-worm | 05 | 00 | 0.00 | |
| 7 | PING | 12 | 00 | 0.00 | |
| 8 | TCP/4899 - radmin | 46 | 00 | 0.00 | |
| 9 | TCP/22 - ssh | 09 | 00 | 0.00 | |
| 10 | TCP/1026 - trojan | 06 | 00 | 0.00 |

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | VG-4-11.dialup.access.telecore.net.ru (213.135.64.160) | 66.155.139.155 | 01 | 00 | |
| 2 | 69-18-47-238.lisco.net (69.18.47.238) | 66.155.139.155 | 22 | 00 |
Firewall: fw.celotexfiberboard.com - Interfaces: eth1 to N/A - Go to top
Top 10 sources

Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 129.33.94.73 | 5,920 | 63.81 | |
| 2 | 198.248.214.7 | 2,960 | 31.90 | |
| 3 | 222.238.84.21 | 80 | 0.86 | |
| 4 | 66.155.248.199 | 72 | 0.78 | |
| 5 | 107.198-pool-nas2-lor.sccoast.net (66.153.198.107) | 72 | 0.78 | |
| 6 | 207.218.223.100 | 58 | 0.63 | |
| 7 | 67.15.240.38 | 58 | 0.63 | |
| 8 | 207.218.223.93 | 58 | 0.63 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 66.155.139.158 | 9,278 | 100.00 |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 129.33.94.73 | PING | 04 | 5,920 | 63.81 | |
| 2 | 198.248.214.7 | PING | 02 | 2,960 | 31.90 | |
| 3 | 222.238.84.21 | PING | 02 | 80 | 0.86 | |
| 4 | 66.155.248.199 | PING | 01 | 72 | 0.78 | |
| 5 | 107.198-pool-nas2-lor.sccoast.net (66.153.198.107) | PING | 01 | 72 | 0.78 | |
| 6 | 207.218.223.100 | PING | 01 | 58 | 0.63 | |
| 7 | 67.15.240.38 | PING | 01 | 58 | 0.63 | |
| 8 | 207.218.223.93 | PING | 01 | 58 | 0.63 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 129.33.94.73 | 66.155.139.158 | PING | 04 | 5,920 | 63.81 | |
| 2 | 198.248.214.7 | 66.155.139.158 | PING | 02 | 2,960 | 31.90 | |
| 3 | 222.238.84.21 | 66.155.139.158 | PING | 02 | 80 | 0.86 | |
| 4 | 66.155.248.199 | 66.155.139.158 | PING | 01 | 72 | 0.78 | |
| 5 | 107.198-pool-nas2-lor.sccoast.net (66.153.198.107) | 66.155.139.158 | PING | 01 | 72 | 0.78 | |
| 6 | 207.218.223.100 | 66.155.139.158 | PING | 01 | 58 | 0.63 | |
| 7 | 67.15.240.38 | 66.155.139.158 | PING | 01 | 58 | 0.63 | |
| 8 | 207.218.223.93 | 66.155.139.158 | PING | 01 | 58 | 0.63 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | PING | 13 | 9,278 | 100.00 |
Firewall: fw.celotexfiberboard.com - Interfaces: eth2 to eth0 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.0.0.80 | 5,349,612 | 30.32 | |
| 2 | 10.0.0.83 | 4,284,843 | 24.29 | |
| 3 | 10.35.94.137 | 1,675,149 | 9.49 | |
| 4 | 192.168.0.176 | 1,420,124 | 8.05 | 7 denials recorded on 3/21/2006 9:36:42 AM |
| 5 | 10.35.94.112 | 1,251,052 | 7.09 | |
| 6 | 10.35.94.121 | 1,200,492 | 6.80 | |
| 7 | 10.35.93.103 | 1,021,692 | 5.79 | |
| 8 | 10.0.0.58 | 656,848 | 3.72 | |
| 9 | 10.35.94.139 | 299,784 | 1.70 | |
| 10 | 10.80.80.75 | 136,028 | 0.77 | 23 denials recorded on 3/21/2006 9:36:42 AM |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.5 | 11,375,880 | 64.48 | |
| 2 | 192.168.1.3 | 6,124,073 | 34.71 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 3 | 192.168.1.10 | 80,033 | 0.45 | |
| 4 | 192.168.1.2 | 63,102 | 0.36 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.0.0.80 | TCP/3389 - ms rdp | 02 | 5,349,612 | 30.32 | |
| 2 | 10.0.0.83 | TCP/3389 - ms rdp | 02 | 4,284,843 | 24.29 | |
| 3 | 10.35.94.137 | TCP/3389 - ms rdp | 02 | 1,675,149 | 9.49 | |
| 4 | 192.168.0.176 | TCP/1410 | 06 | 1,414,354 | 8.02 | 7 denials recorded on 3/21/2006 9:36:42 AM |
| 5 | 10.35.94.112 | TCP/1410 | 03 | 1,250,610 | 7.09 | |
| 6 | 10.35.94.121 | TCP/1410 | 10 | 1,198,724 | 6.79 | |
| 7 | 10.35.93.103 | TCP/1410 | 04 | 1,020,808 | 5.79 | |
| 8 | 10.0.0.58 | TCP/1410 | 06 | 656,848 | 3.72 | |
| 9 | 10.35.94.139 | TCP/1410 | 03 | 296,942 | 1.68 | |
| 10 | 10.80.80.75 | TCP/1410 | 10 | 128,186 | 0.73 | 23 denials recorded on 3/21/2006 9:36:42 AM |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.0.0.80 | 192.168.1.5 | TCP/3389 - ms rdp | 02 | 5,349,612 | 30.32 | |
| 2 | 10.0.0.83 | 192.168.1.5 | TCP/3389 - ms rdp | 02 | 4,284,843 | 24.29 | |
| 3 | 10.35.94.137 | 192.168.1.5 | TCP/3389 - ms rdp | 02 | 1,675,149 | 9.49 | |
| 4 | 192.168.0.176 | 192.168.1.3 | TCP/1410 | 06 | 1,414,354 | 8.02 | 7 denials recorded on 3/21/2006 9:36:42 AM 7 denials recorded on 3/21/2006 9:36:42 AM 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 5 | 10.35.94.112 | 192.168.1.3 | TCP/1410 | 03 | 1,250,610 | 7.09 | |
| 6 | 10.35.94.121 | 192.168.1.3 | TCP/1410 | 10 | 1,198,724 | 6.79 | |
| 7 | 10.35.93.103 | 192.168.1.3 | TCP/1410 | 04 | 1,020,808 | 5.79 | |
| 8 | 10.0.0.58 | 192.168.1.3 | TCP/1410 | 06 | 656,848 | 3.72 | |
| 9 | 10.35.94.139 | 192.168.1.3 | TCP/1410 | 03 | 296,942 | 1.68 | |
| 10 | 10.80.80.75 | 192.168.1.3 | TCP/1410 | 10 | 128,186 | 0.73 | 23 denials recorded on 3/21/2006 9:36:42 AM |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/3389 - ms rdp | 08 | 11,375,880 | 64.48 | |
| 2 | TCP/1410 | 49 | 6,097,654 | 34.56 | |
| 3 | UDP/53 - dns | 148 | 66,286 | 0.38 | |
| 4 | TCP/2967 | 26 | 65,160 | 0.37 | |
| 5 | TCP/135 - ms rpc | 31 | 13,182 | 0.07 | |
| 6 | TCP/1333 | 06 | 12,406 | 0.07 | |
| 7 | UDP/137 - netbios | 40 | 7,224 | 0.04 | |
| 8 | TCP/445 - netbios | 01 | 5,296 | 0.03 |

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 10.0.0.80 | 192.168.1.5 | 02 | 5,349,612 | |
| 2 | 10.0.0.83 | 192.168.1.5 | 02 | 4,284,843 | |
| 3 | 10.35.94.137 | 192.168.1.5 | 02 | 1,675,149 | |
| 4 | 192.168.0.153 | 192.168.1.5 | 01 | 37,219 | |
| 5 | 192.168.0.158 | 192.168.1.5 | 01 | 29,057 |
Firewall: fw.celotexfiberboard.com - Interfaces: eth2 to eth1 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.80.80.75 | 265,081,620 | 18.95 | 23 denials recorded on 3/21/2006 9:36:42 AM |
| 2 | 10.35.94.136 | 235,404,127 | 16.83 | |
| 3 | 10.35.93.84 | 108,556,698 | 7.76 | |
| 4 | 10.35.94.130 | 65,104,885 | 4.65 | |
| 5 | 10.0.0.76 | 52,408,517 | 3.75 | |
| 6 | 10.35.93.76 | 42,821,956 | 3.06 | |
| 7 | 192.168.0.152 | 38,589,719 | 2.76 | |
| 8 | 10.35.94.121 | 38,083,988 | 2.72 | |
| 9 | 10.80.80.73 | 30,840,511 | 2.20 | |
| 10 | 192.168.0.158 | 30,189,317 | 2.16 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | hrpayroll-ml.ceridian.com (170.153.222.25) | 46,284,053 | 3.31 | |
| 2 | 216.185.128.200 | 40,701,538 | 2.91 | |
| 3 | 204.10.29.5 | 28,350,970 | 2.03 | |
| 4 | 69.25.149.40 | 18,663,733 | 1.33 | |
| 5 | 65.91.249.39 | 16,007,748 | 1.14 | |
| 6 | 69.9.169.216 | 15,230,151 | 1.09 | |
| 7 | 204.2.224.51 | 14,222,919 | 1.02 | |
| 8 | 199.41.238.63 | 14,190,679 | 1.01 | |
| 9 | bikiniriot.com (64.59.81.83) | 14,145,056 | 1.01 | |
| 10 | 204.10.29.8 | 14,063,955 | 1.01 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.80.80.75 | HTTP | 30,159 | 245,114,721 | 17.52 | 23 denials recorded on 3/21/2006 9:36:42 AM |
| 2 | 10.35.94.136 | HTTP | 32,964 | 226,701,920 | 16.20 | |
| 3 | 10.35.93.84 | HTTP | 7,789 | 108,491,372 | 7.75 | |
| 4 | 10.35.94.130 | HTTP | 4,223 | 64,992,423 | 4.65 | |
| 5 | 10.0.0.76 | HTTP | 5,067 | 52,317,305 | 3.74 | |
| 6 | 10.35.94.121 | HTTP | 6,439 | 37,196,673 | 2.66 | |
| 7 | 192.168.0.152 | HTTP | 3,832 | 36,543,820 | 2.61 | |
| 8 | 10.35.93.76 | HTTP-HTTPS | 93 | 35,644,443 | 2.55 | |
| 9 | 10.80.80.73 | HTTP | 2,421 | 30,835,553 | 2.20 | |
| 10 | 10.0.0.63 | HTTP | 3,466 | 29,023,026 | 2.07 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.35.94.130 | 216.185.128.200 | HTTP | 52 | 40,701,538 | 2.91 | |
| 2 | 10.35.93.76 | hrpayroll-ml.ceridian.com (170.153.222.25) | HTTP-HTTPS | 88 | 35,634,475 | 2.55 | |
| 3 | 10.35.94.136 | 69.25.149.40 | HTTP | 09 | 18,663,733 | 1.33 | |
| 4 | 10.35.94.136 | 65.91.249.39 | HTTP | 791 | 15,475,626 | 1.11 | |
| 5 | 10.80.80.1 | 204.10.29.5 | HTTP | 10 | 14,177,388 | 1.01 | |
| 6 | 10.35.94.234 | 204.10.29.5 | HTTP | 05 | 14,173,582 | 1.01 | |
| 7 | 10.0.0.76 | bikiniriot.com (64.59.81.83) | HTTP | 1,038 | 14,145,056 | 1.01 | |
| 8 | 10.35.93.100 | 204.10.29.8 | HTTP | 05 | 14,063,955 | 1.01 | |
| 9 | 192.168.0.253 | www.Level3.com (63.209.221.238) | HTTP | 05 | 14,063,955 | 1.01 | |
| 10 | 10.80.80.75 | 199.41.238.63 | HTTP-HTTPS | 119 | 13,523,351 | 0.97 | 23 denials recorded on 3/21/2006 9:36:42 AM |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP | 152,481 | 1,260,633,183 | 90.11 | |
| 2 | HTTP-HTTPS | 6,646 | 128,418,551 | 9.18 | |
| 3 | TCP/27030 | 04 | 3,455,917 | 0.25 | |
| 4 | TCP/1935 | 228 | 2,989,252 | 0.21 | |
| 5 | TCP/995 | 125 | 2,680,747 | 0.19 | |
| 6 | TCP/27038 | 08 | 276,402 | 0.02 | |
| 7 | TCP/5190 - icq | 51 | 237,999 | 0.02 | |
| 8 | TCP/465 | 13 | 120,138 | 0.01 | |
| 9 | IP/50 | 02 | 90,344 | 0.01 | |
| 10 | TCP/8765 | 06 | 50,851 | 0.00 |

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 221.140.55.71 | 65.5.124.0 | 03 | 00 | |
| 2 | 221.140.55.71 | 65.5.124.1 | 03 | 00 | |
| 3 | 221.140.55.71 | 65.5.124.2 | 03 | 00 | |
| 4 | 221.140.55.71 | 65.5.124.3 | 03 | 00 | |
| 5 | 221.140.55.71 | 65.5.124.4 | 03 | 00 | |
| 6 | 221.140.55.71 | 65.5.124.5 | 03 | 00 | |
| 7 | 221.140.55.71 | 65.5.124.8 | 03 | 00 | |
| 8 | 221.140.55.71 | 65.5.124.7 | 03 | 00 | |
| 9 | 221.140.55.71 | 65.5.124.6 | 03 | 00 | |
| 10 | 221.140.55.71 | 65.5.124.9 | 03 | 00 |
Firewall: fw.celotexfiberboard.com - Interfaces: eth2 to N/A - Go to top
Top 10 sources
Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.0.253 | 11,586,736 | 100.00 |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | www.hpq.com (192.6.234.10) | 11,586,736 | 100.00 |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.0.253 | FTP-DATA | 01 | 11,586,736 | 100.00 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.0.253 | www.hpq.com (192.6.234.10) | FTP-DATA | 01 | 11,586,736 | 100.00 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | FTP-DATA | 01 | 11,586,736 | 100.00 |
Firewall: fw.celotexfiberboard.com - Interfaces: N/A to eth0 - Go to top
Top 10 sources
Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | sciftpgw.commerce.stercomm.com (209.95.224.122) | 6,600 | 100.00 |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.13 | 6,600 | 100.00 |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | sciftpgw.commerce.stercomm.com (209.95.224.122) | FTP-DATA | 21 | 6,600 | 100.00 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | sciftpgw.commerce.stercomm.com (209.95.224.122) | 192.168.1.13 | FTP-DATA | 21 | 6,600 | 100.00 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | FTP-DATA | 21 | 6,600 | 100.00 |
Firewall: fw.celotexfiberboard.com - Interface: N/A - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 66.155.139.158 | 137,082,789 | 95.09 | |
| 2 | 192.168.1.179 | 6,174,213 | 4.28 | |
| 3 | 192.168.1.131 | 706,372 | 0.49 | |
| 4 | 10.35.94.136 | 51,285 | 0.04 | |
| 5 | 192.168.1.136 | 33,138 | 0.02 | |
| 6 | 10.35.93.84 | 33,138 | 0.02 | |
| 7 | 10.35.94.109 | 19,012 | 0.01 | |
| 8 | 10.80.80.75 | 13,811 | 0.01 | 23 denials recorded on 3/21/2006 9:36:42 AM |
| 9 | 192.168.1.3 | 11,534 | 0.01 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 10 | mail.dampa.dk (80.199.83.65) | 8,429 | 0.01 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 204.183.33.108 | 126,691,008 | 87.88 | |
| 2 | 192.168.1.253 | 6,880,585 | 4.77 | |
| 3 | cpe-66-74-28-105.dc.res.rr.com (66.74.28.105) | 3,250,314 | 2.25 | |
| 4 | c-24-15-78-209.hsd1.il.comcast.net (24.15.78.209) | 2,251,061 | 1.56 | |
| 5 | adsl-70-156-143-129.mia.bellsouth.net (70.156.143.129) | 1,900,839 | 1.32 | |
| 6 | dsl-216-227-96-131.fairpoint.net (216.227.96.131) | 735,195 | 0.51 | |
| 7 | c-68-49-50-223.hsd1.md.comcast.net (68.49.50.223) | 675,736 | 0.47 | |
| 8 | c-24-12-191-23.hsd1.il.comcast.net (24.12.191.23) | 489,354 | 0.34 | |
| 9 | c-67-163-115-70.hsd1.va.comcast.net (67.163.115.70) | 422,583 | 0.29 | |
| 10 | c-67-163-52-39.hsd1.il.comcast.net (67.163.52.39) | 304,178 | 0.21 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 66.155.139.158 | ESP/SHA | 119 | 137,082,789 | 95.09 | |
| 2 | 192.168.1.179 | SGMI | 04 | 6,174,213 | 4.28 | |
| 3 | 192.168.1.131 | SGMI | 02 | 706,372 | 0.49 | |
| 4 | 10.35.94.136 | HTTP | 70 | 51,285 | 0.04 | |
| 5 | 192.168.1.136 | HTTP | 42 | 33,138 | 0.02 | |
| 6 | 10.35.93.84 | HTTP | 42 | 33,138 | 0.02 | |
| 7 | 10.35.94.109 | HTTP | 11 | 19,012 | 0.01 | |
| 8 | 10.80.80.75 | HTTP | 25 | 13,811 | 0.01 | 23 denials recorded on 3/21/2006 9:36:42 AM |
| 9 | 192.168.1.3 | HTTP | 146 | 11,534 | 0.01 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 10 | mail.dampa.dk (80.199.83.65) | HTTP | 07 | 8,429 | 0.01 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 66.155.139.158 | 204.183.33.108 | ESP/SHA | 04 | 126,691,008 | 87.88 | |
| 2 | 192.168.1.179 | 192.168.1.253 | SGMI | 04 | 6,174,213 | 4.28 | |
| 3 | 66.155.139.158 | cpe-66-74-28-105.dc.res.rr.com (66.74.28.105) | ESP/SHA | 11 | 3,250,314 | 2.25 | |
| 4 | 66.155.139.158 | c-24-15-78-209.hsd1.il.comcast.net (24.15.78.209) | ESP/SHA | 15 | 2,251,061 | 1.56 | |
| 5 | 66.155.139.158 | adsl-70-156-143-129.mia.bellsouth.net (70.156.143.129) | ESP/SHA | 01 | 1,900,839 | 1.32 | |
| 6 | 66.155.139.158 | dsl-216-227-96-131.fairpoint.net (216.227.96.131) | ESP/SHA | 06 | 735,195 | 0.51 | |
| 7 | 192.168.1.131 | 192.168.1.253 | SGMI | 02 | 706,372 | 0.49 | |
| 8 | 66.155.139.158 | c-68-49-50-223.hsd1.md.comcast.net (68.49.50.223) | ESP/SHA | 04 | 675,736 | 0.47 | |
| 9 | 66.155.139.158 | c-24-12-191-23.hsd1.il.comcast.net (24.12.191.23) | ESP/SHA | 01 | 489,354 | 0.34 | |
| 10 | 66.155.139.158 | c-67-163-115-70.hsd1.va.comcast.net (67.163.115.70) | ESP/SHA | 03 | 422,583 | 0.29 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | ESP/SHA | 119 | 137,082,789 | 95.09 | |
| 2 | SGMI | 06 | 6,880,585 | 4.77 | |
| 3 | HTTP | 378 | 204,691 | 0.14 | |
| 4 | FTP | 01 | 92 | 0.00 | |
| 5 | TCP/25 - smtp | 02 | 00 | 0.00 | |
| 6 | CIFS | 11 | 00 | 0.00 | |
| 7 | FTP-DATA | 02 | 00 | 0.00 | |
| 8 | UDP/123 - ntp | 01 | 00 | 0.00 |

Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | VG-4-11.dialup.access.telecore.net.ru (213.135.64.160) | N/A | 01 | 00 | |
| 2 | mailgate1.sitestar.net (72.236.205.252) | N/A | 01 | 00 |
Firewall: fw.celotexfiberboard.com - Interface: eth2 - Go to top
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.80.80.75 | 23 | 3/21/2006 9:36:42 AM | 41.82 | 23 denials recorded on 3/21/2006 9:36:42 AM |
| 2 | 222.73.4.156 | 14 | 3/21/2006 10:21:51 AM | 25.45 | 14 denials recorded on 3/21/2006 10:21:51 AM |
| 3 | 192.168.0.176 | 07 | 3/21/2006 9:36:42 AM | 12.73 | 7 denials recorded on 3/21/2006 9:36:42 AM |
| 4 | 10.35.93.106 | 04 | 3/21/2006 9:36:42 AM | 07.27 | |
| 5 | 10.35.94.121 | 03 | 3/21/2006 6:05:27 AM | 05.45 | |
| 6 | 222.73.4.158 | 02 | 3/21/2006 1:29:22 AM | 03.64 | |
| 7 | 218.66.104.246 | 01 | 3/21/2006 1:11:01 AM | 01.82 | |
| 8 | 10.35.93.103 | 01 | 3/21/2006 9:36:43 AM | 01.82 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 192.168.1.3 | 38 | 3/21/2006 6:05:27 AM | 69.09 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 65.5.124.18 | 02 | 3/21/2006 1:11:01 AM | 03.64 | |
| 3 | 65.5.124.24 | 02 | 3/21/2006 12:25:41 PM | 03.64 | |
| 4 | 65.5.124.9 | 01 | 3/21/2006 1:29:22 AM | 01.82 | |
| 5 | 65.5.124.6 | 01 | 3/21/2006 1:30:14 AM | 01.82 | |
| 6 | 65.5.124.29 | 01 | 3/21/2006 10:21:51 AM | 01.82 | |
| 7 | 65.5.124.12 | 01 | 3/21/2006 11:14:31 AM | 01.82 | |
| 8 | 65.5.124.23 | 01 | 3/21/2006 12:15:26 PM | 01.82 | |
| 9 | 65.5.124.25 | 01 | 3/21/2006 1:07:01 PM | 01.82 | |
| 10 | 65.5.124.0 | 01 | 3/21/2006 1:13:34 PM | 01.82 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/135 - ms rpc | 38 | 3/21/2006 6:05:27 AM | 69.09 | |
| 2 | TCP/503 | 02 | 3/21/2006 12:25:41 PM | 03.64 | |
| 3 | TCP/1004 | 01 | 3/21/2006 1:11:01 AM | 01.82 | |
| 4 | TCP/826 | 01 | 3/21/2006 1:29:22 AM | 01.82 | |
| 5 | TCP/336 | 01 | 3/21/2006 1:30:14 AM | 01.82 | |
| 6 | TCP/743 | 01 | 3/21/2006 10:21:51 AM | 01.82 | |
| 7 | TCP/308 | 01 | 3/21/2006 11:14:31 AM | 01.82 | |
| 8 | TCP/690 | 01 | 3/21/2006 12:15:26 PM | 01.82 | |
| 9 | TCP/353 | 01 | 3/21/2006 1:07:01 PM | 01.82 | |
| 10 | TCP/195 | 01 | 3/21/2006 1:13:34 PM | 01.82 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | Possible port scan detected | 55 | 3/21/2006 1:11:01 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 10.80.80.75 | 192.168.1.3 | TCP/135 - ms rpc | Possible port scan detected | 23 | 3/21/2006 9:36:42 AM | 41.82 | 23 denials recorded on 3/21/2006 9:36:42 AM 23 denials recorded on 3/21/2006 9:36:42 AM 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 192.168.0.176 | 192.168.1.3 | TCP/135 - ms rpc | Possible port scan detected | 07 | 3/21/2006 9:36:42 AM | 12.73 | 7 denials recorded on 3/21/2006 9:36:42 AM |
| 3 | 10.35.93.106 | 192.168.1.3 | TCP/135 - ms rpc | Possible port scan detected | 04 | 3/21/2006 9:36:42 AM | 7.27 | |
| 4 | 10.35.94.121 | 192.168.1.3 | TCP/135 - ms rpc | Possible port scan detected | 03 | 3/21/2006 6:05:27 AM | 5.45 | |
| 5 | 222.73.4.156 | 65.5.124.24 | TCP/503 | Possible port scan detected | 02 | 3/21/2006 12:25:41 PM | 3.64 | 14 denials recorded on 3/21/2006 10:21:51 AM |
| 6 | 218.66.104.246 | 65.5.124.18 | TCP/1004 | Possible port scan detected | 01 | 3/21/2006 1:11:01 AM | 1.82 | |
| 7 | 222.73.4.158 | 65.5.124.9 | TCP/826 | Possible port scan detected | 01 | 3/21/2006 1:29:22 AM | 1.82 | |
| 8 | 222.73.4.158 | 65.5.124.6 | TCP/336 | Possible port scan detected | 01 | 3/21/2006 1:30:14 AM | 1.82 | |
| 9 | 10.35.93.103 | 192.168.1.3 | TCP/135 - ms rpc | Possible port scan detected | 01 | 3/21/2006 9:36:43 AM | 1.82 | |
| 10 | 222.73.4.156 | 65.5.124.29 | TCP/743 | Possible port scan detected | 01 | 3/21/2006 10:21:51 AM | 1.82 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/135 - ms rpc | Possible port scan detected | 38 | 69.09 | |
| 2 | TCP/503 | Possible port scan detected | 02 | 3.64 | |
| 3 | TCP/1004 | Possible port scan detected | 01 | 1.82 | |
| 4 | TCP/826 | Possible port scan detected | 01 | 1.82 | |
| 5 | TCP/336 | Possible port scan detected | 01 | 1.82 | |
| 6 | TCP/743 | Possible port scan detected | 01 | 1.82 | |
| 7 | TCP/308 | Possible port scan detected | 01 | 1.82 | |
| 8 | TCP/690 | Possible port scan detected | 01 | 1.82 | |
| 9 | TCP/353 | Possible port scan detected | 01 | 1.82 | |
| 10 | TCP/195 | Possible port scan detected | 01 | 1.82 |
Firewall: fw.celotexfiberboard.com - Interfaces: Not specified - Go to top
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
Top 10 warning messages
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ns1.sfj.pnap.net (216.52.1.1) | 3,040 | 3/21/2006 12:00:14 AM | 08.99 | 3040 denials recorded on 3/21/2006 12:00:14 AM |
| 2 | niconet2k.com (65.110.41.44) | 2,688 | 3/21/2006 12:00:13 AM | 07.95 | 2688 denials recorded on 3/21/2006 12:00:13 AM |
| 3 | 64.134.205.1 | 2,160 | 3/21/2006 12:01:33 AM | 06.39 | 2160 denials recorded on 3/21/2006 12:01:33 AM |
| 4 | 10.5.55.98 | 2,160 | 3/21/2006 8:10:25 AM | 06.39 | |
| 5 | 10.5.55.99 | 2,154 | 3/21/2006 8:10:30 AM | 06.37 | |
| 6 | mail.daveevanstransports.com (24.158.21.10) | 1,345 | 3/21/2006 12:00:11 AM | 03.98 | |
| 7 | mail.village-npb.org (65.5.152.162) | 520 | 3/21/2006 12:03:04 AM | 01.54 | |
| 8 | 65.5.124.2 | 385 | 3/21/2006 12:02:47 AM | 01.14 | |
| 9 | 65.5.124.18 | 363 | 3/21/2006 12:02:48 AM | 01.07 | |
| 10 | 65.5.124.23 | 348 | 3/21/2006 12:02:47 AM | 01.03 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.35.93.74 | 3,304 | 3/21/2006 12:00:14 AM | 09.77 | |
| 2 | 192.168.1.138 | 2,328 | 3/21/2006 8:10:25 AM | 06.88 | |
| 3 | 10.80.80.64 | 2,160 | 3/21/2006 12:01:33 AM | 06.39 | |
| 4 | 192.168.1.141 | 1,986 | 3/21/2006 9:20:01 AM | 05.87 | |
| 5 | 10.254.1.5 | 1,345 | 3/21/2006 12:00:11 AM | 03.98 | |
| 6 | 10.254.10.5 | 1,344 | 3/21/2006 12:00:13 AM | 03.97 | |
| 7 | 10.254.254.254 | 1,344 | 3/21/2006 12:00:38 AM | 03.97 | |
| 8 | 192.168.1.182 | 1,302 | 3/21/2006 8:36:09 AM | 03.85 | |
| 9 | origin-admin-sc9-b.stg-ciscoeos.com (204.16.208.112) | 826 | 3/21/2006 12:48:56 AM | 02.44 | |
| 10 | 10.35.94.136 | 555 | 3/21/2006 5:07:17 AM | 01.64 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/123 - ntp | 7,288 | 3/21/2006 12:00:11 AM | 21.55 | |
| 2 | UDP/137 - netbios | 6,922 | 3/21/2006 12:01:33 AM | 20.47 | |
| 3 | UDP/1026 - blaster-worm | 5,229 | 3/21/2006 12:02:47 AM | 15.46 | |
| 4 | TCP/445 - netbios | 1,724 | 3/21/2006 12:17:52 AM | 05.10 | |
| 5 | TCP/135 - ms rpc | 1,616 | 3/21/2006 12:03:04 AM | 04.78 | |
| 6 | UDP/1027 - blaster-worm | 1,443 | 3/21/2006 12:07:20 AM | 04.27 | |
| 7 | PING | 1,391 | 3/21/2006 12:04:42 AM | 04.11 | |
| 8 | TCP/5061 | 935 | 3/21/2006 8:44:53 AM | 02.76 | |
| 9 | TCP/7212 | 547 | 3/21/2006 12:09:27 AM | 01.62 | |
| 10 | TCP/3601 | 528 | 3/21/2006 12:00:57 AM | 01.56 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | [default rule] [no rules found] | 29,501 | 3/21/2006 12:00:11 AM | 87.23 | |
| 2 | TCP Reset | 3,840 | 3/21/2006 12:00:57 AM | 11.35 | |
| 3 | packet addressed to firewall and no redirection found | 261 | 3/21/2006 12:09:34 AM | 00.77 | |
| 4 | [rule id 4] [explicit deny rule] | 218 | 3/21/2006 3:16:06 AM | 00.64 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/123 - ntp | [default rule] [no rules found] | 7,288 | 21.55 | |
| 2 | UDP/137 - netbios | [default rule] [no rules found] | 6,922 | 20.47 | |
| 3 | UDP/1026 - blaster-worm | [default rule] [no rules found] | 5,229 | 15.46 | |
| 4 | TCP/445 - netbios | [default rule] [no rules found] | 1,724 | 5.10 | |
| 5 | UDP/1027 - blaster-worm | [default rule] [no rules found] | 1,443 | 4.27 | |
| 6 | PING | [default rule] [no rules found] | 1,391 | 4.11 | |
| 7 | TCP/135 - ms rpc | TCP Reset | 816 | 2.41 | |
| 8 | TCP/135 - ms rpc | [default rule] [no rules found] | 800 | 2.37 | |
| 9 | TCP/5061 | [default rule] [no rules found] | 468 | 1.38 | |
| 10 | TCP/5061 | TCP Reset | 467 | 1.38 |
Top 10 warning messages
| No | Code | Message sample | Count | Comment |
|---|---|---|---|---|
| 1 | 239 | Sending TCP reset not allowed, Source IP=10.35.93.106, Destination IP=192.168.1.3, IP Code=TCP, Flag=SYN, Source Port=2082, Destination Port=135, Adapter=eth2 | 3256 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 2 | 343 | Using rule ID 8 because two equally good rules were found. Rule 5 = Rule 8, Program Name=GWControl Service, Operation=Validate, Status=Success, State=OK | 2187 | |
| 3 | 228 | Cannot connect to port, Program Name=httpd, Operation=Connect, Resource=63.208.226.225, Status=[110] Connection tim, State=Fail, Protocol=http, Host=63.208.226.225, Destination Port=80, IP Address=63.208.226.225 | 529 | |
| 4 | 456 | HTTPS service not supported, Program Name=httpd, Operation=Connect, Resource=192.168.1.3, Status=Failure, State=Abort | 146 | |
| 5 | 335 | VPN packet dropped because VPN is not enabled, Source IP=69.222.255.63, Destination IP=66.155.139.158, Payload=0xb22f3b85 | 121 | |
| 6 | 301 | Repeated:, Consolidated Message=343 WARNING: Packet for interface was routed to interface, Count=2, Source IP=10.254.254.1, Destination IP=12.119.118.26, IP Code=ICMP, IP Code=Unreachable (host prohibited), String Value=Inner Packet data follows, Source IP=12.119.118.26, Destination IP=135.89.152.51, IP Code=ICMP, IP Subtype ID=26040, IP Code=Echo reply, Adapter=eth2, IP Address=66.155.139.158 | 100 | |
| 7 | 152 | LiveUpdate found files up-to-date, Program Name=IDS, Operation=Live Update, Resource=Intrusion Detection and Prevention Subscription Update, Status=Success, State=OK | 72 | |
| 8 | 201 | Repeated, Consolidated Message=232 NOTICE: Sending ICMP unreachable, Count=2, IP Code=Unreachable (host prohibited), Source IP=12.119.118.26, Destination IP=135.89.152.51, IP Code=ICMP, IP Subtype ID=26040, IP Code=Echo reply, Adapter=eth2 | 66 | |
| 9 | 122 | Daemon listening on port(s), Program Name=User Library, Operation=Initialize, Resource= 80/tcp, 443/tcp, Status=Success, State=OK | 58 | |
| 10 | 238 | User proxy by means of outside interface is not allowed, use httpd.allow_external_proxy to change it, Program Name=httpd, Operation=Connect, Status=Failure, State=Denying, User=63.229.225.195, Interface=eth1 | 54 | |
| 11 | 219 | Cannot parse URL, Program Name=httpd, Operation=Validate, Resource=OPTIONS / HTTP/1.1\r\ntranslate: f\r\nUser-Agent: Microsoft-WebDAV-MiniRedir/5.1.2600\r\nHost: 66.155.139.150\r\nContent-Length: 0\r\nConnection: Keep-Alive\r\n\r\n, Status=Failure, State=Fail | 48 | 1 denials recorded on 11/13/2006 4:32:48 PM |
| 12 | 109 | Re-reading configuration file, Information=Bad Services traffic saturation alert threshold set to: 20.00 % | 34 | |
| 13 | 334 | Denied access to command, Count=1, Source Name=83.110.176.142, Source IP=2.0.13.121, Destination Name=66.155.139.150, Destination IP=2.0.0.139, Source Interface=66.155.139.158 | 29 | |
| 14 | 227 | VPN packet dropped because the packet is either too old or has been received before by tunnel (potential replay attack), Source IP=204.183.33.108, Destination IP=66.155.139.158, IP Code=UDP, Source Port=56092, Destination Port=786, Tunnel=3.isakmp.30@204.183.33.108 | 29 | |
| 15 | 117 | Daemon starting, Program Name=rtspd, Operation=Initialize, Resource=rtspd, Status=Success, State=Starting | 28 | |
| 16 | 230 | Not authorized, Protocol=TCP GSP, Source IP=69.18.47.238, Source Port=2827, Source Name=69.18.47.238 | 25 | |
| 17 | 124 | Parameters and filters set for interfaces, Setting=eth2, Operation=Modify, Revision=0 | 18 | |
| 18 | 170 | IDS: Open called on device ids | 17 | |
| 19 | 344 | Non-transparent call, Source Name=220.135.254.38, Source IP=220.135.254.38, Destination Name=fw.celotexfiberboard.com, Destination IP=66.155.139.158 | 12 | |
| 20 | 115 | Successful authentication from remote management client, User=jolson, Source IP=192.168.1.131, Source Name=192.168.1.131, Destination IP=192.168.1.253, Destination Port=2456 | 11 | |
| 21 | 116 | Remote management completed, User=jolson, Source IP=192.168.1.131, Source Name=192.168.1.131, Destination IP=192.168.1.253, Destination Port=2456 | 10 | |
| 22 | 164 | Received command to reload filter configuration, Operation=Modify, Revision=0 | 6 | |
| 23 | 131 | Remote management connection request, From=192.168.1.179, To=192.168.1.253, Source Port=4247, Destination Port=423 | 5 | |
| 24 | 101 | Time reset, Type=step, Offset=-0.142220 | 5 | |
| 25 | 240 | TCP packet dropped due to bad TCP flags combination, Source IP=88.136.165.218, Destination IP=65.5.124.4, IP Code=TCP, Flag=FIN, Source Port=51679, Destination Port=60729, Adapter=eth2, Probable Probe=QueSO, Flag=0x01 | 3 | |
| 26 | 271 | Temporarily suppressing messages because the security gateway has reached log limits for driver messages at this level, Count=200, Interval=seconds | 3 | |
| 27 | 452 | LiveUpdate failed, Program Name=Content Filtering, Operation=Live Update, Resource=Content Filtering URL Update, Status=Failure, State=Fail | 2 | |
| 28 | 226 | IP packet dropped due to bad source address, Source IP=127.0.0.1, Destination IP=192.168.1.10, IP Code=ICMP, IP Subtype ID=1234, IP Code=Echo request, Adapter=eth2 | 2 | |
| 29 | 401 | Remote management login failed, User=jolson, Source IP=192.168.1.131, Source Name=192.168.1.131, Destination IP=192.168.1.253, Destination Port=2456 | 2 | |
| 30 | 370 | NET: 5 messages suppressed. | 1 | |
| 31 | 118 | Daemon exiting, Program Name=GWControl Service, Operation=Validate, Resource=signal(15), Status=Success, State=OK | 1 | |
| To assist us in improving the analyzer, please send the messages above to support@firegen.com and they will be added to the next release of Firegen. | ||||
Analysis details
| Analysis start time | 11/15/2011 7:15:30 PM |
| Analysis duration | 4.49 minutes (269 seconds) |
| Analysis engine version | SGS parser version: 0.01 FireGen30Service.exe - FireGen scheduler service: 3.0.0.0 |
| Filtering criteria | All entries |
| Excluded keywords | None |
Glossary
| !!! | Indicates that a high denials:connections ration has been detected. The current configured ratio is 3. The !!! indicates that the percentage of denials for that hour is bigger than 3 x the connections percentage. This indicates some unusual denial activity that may have to be investigated. The ratio can be configured on the Report Formats interface. |
| Other messages | The Other messages represents a list of message not yet configured in the Firegen parser. Please send these messages to us (support@firegen.com) and we will add them in the next Firegen update. These messages are included in the list of message types but they are not yet fully understood by the analyzer. |