FireGen Report
| Info | Value |
|---|---|
| Log profile | Log profile 20111031193059 |
| Analyzed log(s) |
F:\Logs\Pix\syslog-2009-04-27.log (197.00 MB) |
| Firewall type | Cisco Pix/ASA |
| Analysis interval | All entries in the specified log |
Firewalls
| No | Firewall | Connections | Traffic (MB) | Denials | Warnings | URLs | 1 | 192.168.5.1 | 199,560.00 | 6,991.37 | 3,189.00 | 5.00 | 605,066.00 |
|---|
Message types
| No | Code | Message sample | Count | 2 | 2-106001 | Inbound TCP connection denied from 94.75.231.162/1041 to 208.76.111.141/1211 flags RST ACK on interface outside | 232 | 3 | 2-106006 | Deny inbound UDP from 79.134.26.109/1538 to 208.76.111.141/35064 on interface outside | 39 | 4 | 3-106014 | Deny inbound icmp src outside:208.78.111.206 dst outside:208.76.111.142 (type 8, code 0) | 04 | 5 | 3-710003 | TCP access denied by ACL from 117.32.251.242/59398 to outside:208.76.111.138/22 | 10 | 6 | 4-106023 | Deny icmp src outside:210.212.61.252 dst inside:208.76.111.139 (type 8, code 0) by access-group "web_out" | 2,895 | 7 | 4-411001 | Line protocol on Interface inside, changed state to up | 02 | 8 | 4-419001 | Dropping TCP packet from inside:192.168.5.55/80 to outside:99.241.156.247/33085, reason: MSS exceeded, MSS 0, data 1380 | 09 | 9 | 5-304001 | 219.95.45.70 Accessed URL 192.168.5.55:/display.asp?eventid=&source=masas2k3 | 605,066 | 10 | 5-500003 | Bad TCP hdr length (hdrlen=12, pktlen=54) from 192.168.10.249/1174 to 208.76.111.139/80, flags: INVALID, on interface outside | 05 | 11 | 6-302013 | Built inbound TCP connection 48077484 for outside:203.26.122.12/13891 (203.26.122.12/13891) to inside:192.168.5.55/80 (208.76.111.139/80) | 198,839 | 12 | 6-302014 | Teardown TCP connection 48077098 for outside:125.160.178.37/40929 to inside:192.168.5.55/80 duration 0:04:19 bytes 50291 TCP FINs | 198,842 | 13 | 6-302015 | Built outbound UDP connection 48077479 for outside:66.28.0.45/53 (66.28.0.45/53) to inside:192.168.5.55/1894 (208.76.111.139/1894) | 2,933 | 14 | 6-302016 | Teardown UDP connection 48077479 for outside:66.28.0.45/53 to inside:192.168.5.55/1894 duration 0:00:00 bytes 231 | 2,933 | 15 | 6-302020 | Built ICMP connection for faddr 208.78.111.206/512 gaddr 208.76.111.138/0 laddr 208.76.111.138/0 | 03 | 16 | 6-302021 | Teardown ICMP connection for faddr 208.78.111.206/512 gaddr 208.76.111.138/0 laddr 208.76.111.138/0 | 03 | 17 | 6-609001 | Built local-host outside:209.170.130.159 | 83,202 | 18 | 6-609002 | Teardown local-host outside:125.160.178.37 duration 0:06:35 | 83,210 | 19 | 7-710005 | UDP request discarded from 0.0.0.0/68 to outside:255.255.255.255/67 | 1,521 |
|---|
Firewall: 192.168.5.1
192.168.5.1 - Traffic and denials per hour




| Hour | Traffic (MB) | % | Connections | % | Denials | % | |
|---|---|---|---|---|---|---|---|
| 00-01 | 119.00 | 1.71 | 4,108 | 2.03 | 67 | 2.10 | |
| 01-02 | 120.00 | 1.72 | 4,085 | 2.01 | 60 | 1.88 | |
| 02-03 | 142.00 | 2.04 | 4,859 | 2.40 | 48 | 1.51 | |
| 03-04 | 232.00 | 3.33 | 7,570 | 3.73 | 75 | 2.35 | |
| 04-05 | 360.00 | 5.15 | 10,902 | 5.38 | 86 | 2.70 | |
| 05-06 | 417.00 | 5.97 | 11,393 | 5.62 | 90 | 2.82 | |
| 06-07 | 392.00 | 5.62 | 11,624 | 5.73 | 80 | 2.51 | |
| 07-08 | 352.00 | 5.05 | 9,747 | 4.81 | 82 | 2.57 | |
| 08-09 | 333.00 | 4.76 | 9,777 | 4.82 | 120 | 3.76 | |
| 09-10 | 381.00 | 5.45 | 11,558 | 5.70 | 108 | 3.39 | |
| 10-11 | 488.00 | 6.99 | 14,039 | 6.92 | 104 | 3.26 | |
| 11-12 | 547.00 | 7.83 | 16,092 | 7.94 | 1,136 | 35.62 | !!! |
| 12-13 | 489.00 | 7.00 | 13,367 | 6.59 | 130 | 4.08 | |
| 13-14 | 412.00 | 5.90 | 10,664 | 5.26 | 64 | 2.01 | |
| 14-15 | 318.00 | 4.55 | 8,683 | 4.28 | 146 | 4.58 | |
| 15-16 | 334.00 | 4.79 | 9,708 | 4.79 | 183 | 5.74 | |
| 16-17 | 323.00 | 4.63 | 9,433 | 4.65 | 135 | 4.23 | |
| 17-18 | 298.00 | 4.27 | 8,182 | 4.04 | 122 | 3.83 | |
| 18-19 | 241.00 | 3.45 | 6,802 | 3.35 | 84 | 2.63 | |
| 19-20 | 165.00 | 2.37 | 4,840 | 2.39 | 47 | 1.47 | |
| 20-21 | 143.00 | 2.05 | 3,781 | 1.86 | 56 | 1.76 | |
| 21-22 | 120.00 | 1.73 | 3,460 | 1.71 | 54 | 1.69 | |
| 22-23 | 126.00 | 1.81 | 3,785 | 1.87 | 60 | 1.88 | |
| 23-24 | 127.00 | 1.83 | 4,290 | 2.12 | 52 | 1.63 |
Log messages severity levels - 192.168.5.1
| Level | Severity | Description | Total |
|---|---|---|---|
| 1 | Alert | Immediate action needed | 00 |
| 2 | Critical | Critical condition | 271 |
| 3 | Error | Error condition | 14 |
| 4 | Warning | Warning condition | 2,906 |
| 5 | Notification | Normal but signifiant condition | 605,071 |
| 6 | Informational | Informational message only | 569,965 |
| 7 | Debugging | Appears during debugging only | 1,521 |
192.168.5.1 - Interfaces
| No | Interfaces | Connections | MB | % | Denials | Warnings |
|---|---|---|---|---|---|---|
| 1 | inside to outside | 2,892 | 00.55 | 00.01 | 09 | 00 |
| 2 | outside to inside | 196,668 | 6,990.82 | 99.99 | 2,895 | 00 |
| 3 | outside | 00 | 00.00 | 00.00 | 285 | 05 |
| 4 | Not specified | 00 | 00.00 | 00.00 | 00 | 00 |
| Total | 199,560 | 6,991.37 | 3,189 | 05 |
Firewall: 192.168.5.1 - Interfaces: inside to outside - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols
Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.5.55 | 579,560 | 99.95 | 17 denials recorded on 8/16/2010 3:45:54 AM |
| 2 | 192.168.5.56 | 288 | 0.05 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | res1.dns.cogentco.com (66.28.0.45) | 269,409 | 46.46 | |
| 2 | cache03.ca-dns.net (142.77.2.85) | 202,076 | 34.85 | |
| 3 | 64.149.13.103 | 2,400 | 0.41 | |
| 4 | 76-76-198-65.static.pinetreenetworks.com (65.198.76.76) | 1,350 | 0.23 | |
| 5 | 64.73.43.102 | 1,200 | 0.21 | |
| 6 | 65.55.5.253 | 1,050 | 0.18 | |
| 7 | 64.239.246.16 | 900 | 0.16 | |
| 8 | 65.55.13.126 | 900 | 0.16 | |
| 9 | 202.181.132.41 | 891 | 0.15 | |
| 10 | 199.239.136.200 | 750 | 0.13 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.5.55 | UDP/53 - dns | 2,242 | 471,485 | 81.31 | 17 denials recorded on 8/16/2010 3:45:54 AM |
| 2 | 192.168.5.55 | UDP/137 - netbios | 647 | 108,075 | 18.64 | |
| 3 | 192.168.5.56 | UDP/123 - ntp | 03 | 288 | 0.05 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.5.55 | res1.dns.cogentco.com (66.28.0.45) | UDP/53 - dns | 1,204 | 269,409 | 46.46 | 17 denials recorded on 8/16/2010 3:45:54 AM |
| 2 | 192.168.5.55 | cache03.ca-dns.net (142.77.2.85) | UDP/53 - dns | 1,038 | 202,076 | 34.85 | |
| 3 | 192.168.5.55 | 64.149.13.103 | UDP/137 - netbios | 04 | 2,400 | 0.41 | |
| 4 | 192.168.5.55 | 76-76-198-65.static.pinetreenetworks.com (65.198.76.76) | UDP/137 - netbios | 06 | 1,350 | 0.23 | |
| 5 | 192.168.5.55 | 64.73.43.102 | UDP/137 - netbios | 06 | 1,200 | 0.21 | |
| 6 | 192.168.5.55 | 65.55.5.253 | UDP/137 - netbios | 04 | 1,050 | 0.18 | |
| 7 | 192.168.5.55 | 64.239.246.16 | UDP/137 - netbios | 06 | 900 | 0.16 | |
| 8 | 192.168.5.55 | 65.55.13.126 | UDP/137 - netbios | 02 | 900 | 0.16 | |
| 9 | 192.168.5.55 | 202.181.132.41 | UDP/137 - netbios | 01 | 891 | 0.15 | |
| 10 | 192.168.5.55 | 199.239.136.200 | UDP/137 - netbios | 04 | 750 | 0.13 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/53 - dns | 2,242 | 471,485 | 81.31 | |
| 2 | UDP/137 - netbios | 647 | 108,075 | 18.64 | |
| 3 | UDP/123 - ntp | 03 | 288 | 0.05 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 192.168.5.55 | 09 | 4/27/2009 4:38:58 AM | 100.00 | 17 denials recorded on 8/16/2010 3:45:54 AM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | CPE001b116233c6-CM0019477f690c.cpe.net.cable.rogers.com (99.241.156.247) | 09 | 4/27/2009 4:38:58 AM | 100.00 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/33085 | 09 | 4/27/2009 4:38:58 AM | 100.00 |
Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | MSS value of 0 exceeded | 09 | 4/27/2009 4:38:58 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 192.168.5.55 | CPE001b116233c6-CM0019477f690c.cpe.net.cable.rogers.com (99.241.156.247) | TCP/33085 | MSS value of 0 exceeded | 09 | 4/27/2009 4:38:58 AM | 100.00 | 17 denials recorded on 8/16/2010 3:45:54 AM |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/33085 | MSS value of 0 exceeded | 09 | 100.00 |
Firewall: 192.168.5.1 - Interfaces: outside to inside - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/80 - http: Sources, destinations, and traffic
Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 82.76.60.29 | 50,030,811 | 0.68 | |
| 2 | crawl-66-249-70-210.googlebot.com (66.249.70.210) | 23,134,335 | 0.32 | |
| 3 | b5131382.yst.yahoo.net (74.6.18.220) | 21,528,333 | 0.29 | |
| 4 | spider10.yandex.ru (93.158.148.30) | 12,500,137 | 0.17 | |
| 5 | rrcs-24-97-226-234.nys.biz.rr.com (24.97.226.234) | 10,850,985 | 0.15 | |
| 6 | 198.6.33.13 | 10,172,635 | 0.14 | |
| 7 | 24.244.139.190 | 6,339,789 | 0.09 | |
| 8 | 86.127.4.69 | 5,699,738 | 0.08 | |
| 9 | 79.112.11.19 | 5,571,597 | 0.08 | |
| 10 | 99.255.229.41 | 5,447,925 | 0.07 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.5.55 | 7,317,368,158 | 99.82 | 17 denials recorded on 8/16/2010 3:45:54 AM |
| 2 | 192.168.5.56 | 13,038,856 | 0.18 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 82.76.60.29 | TCP/80 - http | 18 | 50,030,811 | 0.68 | |
| 2 | crawl-66-249-70-210.googlebot.com (66.249.70.210) | TCP/80 - http | 1,531 | 20,629,491 | 0.28 | |
| 3 | b5131382.yst.yahoo.net (74.6.18.220) | TCP/80 - http | 2,175 | 20,065,022 | 0.27 | |
| 4 | spider10.yandex.ru (93.158.148.30) | TCP/80 - http | 215 | 12,500,137 | 0.17 | |
| 5 | rrcs-24-97-226-234.nys.biz.rr.com (24.97.226.234) | TCP/80 - http | 1,335 | 10,850,985 | 0.15 | |
| 6 | 198.6.33.13 | TCP/80 - http | 164 | 10,172,635 | 0.14 | |
| 7 | 86.127.4.69 | TCP/80 - http | 11 | 5,699,738 | 0.08 | |
| 8 | 79.112.11.19 | TCP/80 - http | 14 | 5,571,597 | 0.08 | |
| 9 | 99.255.229.41 | TCP/80 - http | 04 | 5,447,925 | 0.07 | |
| 10 | 194.59.120.11 | TCP/80 - http | 289 | 5,411,918 | 0.07 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 82.76.60.29 | 192.168.5.55 | TCP/80 - http | 18 | 50,030,811 | 0.68 | 17 denials recorded on 8/16/2010 3:45:54 AM |
| 2 | crawl-66-249-70-210.googlebot.com (66.249.70.210) | 192.168.5.55 | TCP/80 - http | 1,531 | 20,629,491 | 0.28 | |
| 3 | b5131382.yst.yahoo.net (74.6.18.220) | 192.168.5.55 | TCP/80 - http | 2,175 | 20,065,022 | 0.27 | |
| 4 | spider10.yandex.ru (93.158.148.30) | 192.168.5.55 | TCP/80 - http | 214 | 12,492,403 | 0.17 | |
| 5 | rrcs-24-97-226-234.nys.biz.rr.com (24.97.226.234) | 192.168.5.55 | TCP/80 - http | 1,335 | 10,850,985 | 0.15 | |
| 6 | 198.6.33.13 | 192.168.5.55 | TCP/80 - http | 164 | 10,172,635 | 0.14 | |
| 7 | 86.127.4.69 | 192.168.5.55 | TCP/80 - http | 11 | 5,699,738 | 0.08 | |
| 8 | 79.112.11.19 | 192.168.5.55 | TCP/80 - http | 14 | 5,571,597 | 0.08 | |
| 9 | 99.255.229.41 | 192.168.5.55 | TCP/80 - http | 04 | 5,447,925 | 0.07 | |
| 10 | 194.59.120.11 | 192.168.5.55 | TCP/80 - http | 289 | 5,411,918 | 0.07 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/80 - http | 191,672 | 7,293,817,738 | 99.50 | |
| 2 | TCP/443 - ssl-https | 1,323 | 33,299,657 | 0.45 | |
| 3 | TCP/43 - whois | 1,769 | 1,806,058 | 0.02 | |
| 4 | TCP/8010 | 1,637 | 804,497 | 0.01 | |
| 5 | TCP/25 - smtp | 226 | 494,144 | 0.01 | |
| 6 | UDP/500 - ipsec | 41 | 184,920 | 0.00 |

Top 10 protocol TCP/80 - http: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 82.76.60.29 | 192.168.5.55 | 18 | 50,030,811 | 17 denials recorded on 8/16/2010 3:45:54 AM |
| 2 | crawl-66-249-70-210.googlebot.com (66.249.70.210) | 192.168.5.55 | 1,531 | 20,629,491 | |
| 3 | b5131382.yst.yahoo.net (74.6.18.220) | 192.168.5.55 | 2,175 | 20,065,022 | |
| 4 | spider10.yandex.ru (93.158.148.30) | 192.168.5.55 | 214 | 12,492,403 | |
| 5 | rrcs-24-97-226-234.nys.biz.rr.com (24.97.226.234) | 192.168.5.55 | 1,335 | 10,850,985 | |
| 6 | 198.6.33.13 | 192.168.5.55 | 164 | 10,172,635 | |
| 7 | 86.127.4.69 | 192.168.5.55 | 11 | 5,699,738 | |
| 8 | 79.112.11.19 | 192.168.5.55 | 14 | 5,571,597 | |
| 9 | 99.255.229.41 | 192.168.5.55 | 04 | 5,447,925 | |
| 10 | 194.59.120.11 | 192.168.5.55 | 289 | 5,411,918 |
Top 10 protocol TCP/25 - smtp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | zeus.lunarpages.com (67.210.126.165) | 192.168.5.55 | 84 | 263,539 | 62 denials recorded on 4/29/2009 2:21:22 AM |
| 2 | mailin.rzone.de (81.169.145.101) | 192.168.5.55 | 02 | 4,624 | |
| 3 | yx-in-f27.1e100.net (74.125.45.27) | 192.168.5.55 | 02 | 4,442 | |
| 4 | mail.networksolutionsemail.com (205.178.149.7) | 192.168.5.55 | 02 | 4,103 | |
| 5 | mail-relay.wobline.de (62.176.224.93) | 192.168.5.55 | 04 | 4,061 | |
| 6 | almach.stargate.ca (64.253.129.9) | 192.168.5.55 | 02 | 3,664 | |
| 7 | trisol.stargate.ca (64.253.129.20) | 192.168.5.55 | 02 | 3,664 | |
| 8 | beid.stargate.ca (64.253.129.14) | 192.168.5.55 | 02 | 3,656 | |
| 9 | keid.stargate.ca (64.253.129.15) | 192.168.5.55 | 02 | 3,656 | |
| 10 | skat.stargate.ca (64.253.129.18) | 192.168.5.55 | 02 | 3,646 |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | mail2.rcs.k12.va.us (206.113.136.253) | 981 | 4/27/2009 11:18:05 AM | 33.89 | 981 denials recorded on 4/27/2009 11:18:05 AM |
| 2 | zeus.lunarpages.com (67.210.126.165) | 84 | 4/27/2009 1:41:31 AM | 02.90 | 62 denials recorded on 4/29/2009 2:21:22 AM |
| 3 | 94.75.231.162 | 61 | 4/27/2009 1:32:00 AM | 02.11 | 27 denials recorded on 4/29/2009 1:22:31 AM |
| 4 | 204.251.213.17 | 60 | 4/27/2009 2:16:55 AM | 02.07 | 48 denials recorded on 4/28/2009 2:57:24 AM |
| 5 | 68.156.165.51 | 50 | 4/27/2009 3:06:25 AM | 01.73 | 60 denials recorded on 4/29/2009 3:07:17 AM |
| 6 | mail.bdl-berlin.net (80.153.4.174) | 38 | 4/27/2009 2:59:59 PM | 01.31 | |
| 7 | 137.164.143.36 | 33 | 4/27/2009 7:14:25 AM | 01.14 | |
| 8 | 218.20.54.58 | 32 | 4/27/2009 5:18:20 PM | 01.11 | |
| 9 | 81.94.210.234 | 31 | 4/27/2009 6:32:57 AM | 01.07 | |
| 10 | IBM-Clark-American-1166488.cust-rtr.swbell.net (66.142.240.22) | 29 | 4/27/2009 3:05:15 PM | 01.00 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | www.eventid.net (208.76.111.139) | 2,726 | 4/27/2009 1:24:34 AM | 94.16 | |
| 2 | www.altairtech.ca (208.76.111.140) | 169 | 4/27/2009 1:27:16 AM | 05.84 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/1305 | 982 | 4/27/2009 11:18:05 AM | 33.92 | |
| 2 | ICMP/3 - unreach | 601 | 4/27/2009 1:36:46 AM | 20.76 | |
| 3 | ICMP/8 - ping | 279 | 4/27/2009 1:51:54 AM | 09.64 | |
| 4 | UDP/137 - netbios | 206 | 4/27/2009 1:24:34 AM | 07.12 | |
| 5 | UDP/33437 | 112 | 4/27/2009 2:16:55 AM | 03.87 | |
| 6 | TCP/113 - ident | 91 | 4/27/2009 1:41:31 AM | 03.14 | |
| 7 | UDP/33436 | 79 | 4/27/2009 1:31:39 AM | 02.73 | |
| 8 | UDP/49153 | 47 | 4/27/2009 2:06:42 AM | 01.62 | |
| 9 | UDP/33435 | 46 | 4/27/2009 5:06:56 AM | 01.59 | |
| 10 | UDP/33438 | 45 | 4/27/2009 1:31:19 AM | 01.55 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | Access group web_out | 2,895 | 4/27/2009 1:24:34 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/1305 | Access group web_out | 982 | 33.92 | |
| 2 | ICMP/3 - unreach | Access group web_out | 601 | 20.76 | |
| 3 | ICMP/8 - ping | Access group web_out | 279 | 9.64 | |
| 4 | UDP/137 - netbios | Access group web_out | 206 | 7.12 | |
| 5 | UDP/33437 | Access group web_out | 112 | 3.87 | |
| 6 | TCP/113 - ident | Access group web_out | 91 | 3.14 | |
| 7 | UDP/33436 | Access group web_out | 79 | 2.73 | |
| 8 | UDP/49153 | Access group web_out | 47 | 1.62 | |
| 9 | UDP/33435 | Access group web_out | 46 | 1.59 | |
| 10 | UDP/33438 | Access group web_out | 45 | 1.55 |
Firewall: 192.168.5.1 - Interface: outside - Go to top
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
Top 10 warning messages
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 94.75.231.162 | 57 | 4/27/2009 1:31:01 AM | 20.00 | 27 denials recorded on 4/29/2009 1:22:31 AM |
| 2 | 118.123.5.96 | 08 | 4/27/2009 1:58:48 AM | 02.81 | 8 denials recorded on 4/27/2009 1:58:48 AM |
| 3 | 208.52.163.187 | 06 | 4/27/2009 9:01:03 AM | 02.11 | 6 denials recorded on 4/27/2009 9:01:03 AM |
| 4 | 93-120-137-38.dynamic.mts-nn.ru (93.120.137.38) | 06 | 4/27/2009 9:53:40 AM | 02.11 | |
| 5 | 208.74.217.197 | 06 | 4/27/2009 11:39:28 AM | 02.11 | |
| 6 | 220.225.195.115 | 06 | 4/27/2009 3:42:56 PM | 02.11 | |
| 7 | 117.32.251.242 | 06 | 4/27/2009 11:16:31 PM | 02.11 | |
| 8 | 208.96.100.139 | 06 | 4/27/2009 11:19:50 PM | 02.11 | |
| 9 | 208.82.46.60 | 04 | 4/27/2009 2:32:59 AM | 01.40 | |
| 10 | 208.78.111.206 | 04 | 4/27/2009 5:48:47 AM | 01.40 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 208.76.111.142 | 150 | 4/27/2009 1:31:01 AM | 52.63 | |
| 2 | 208.76.111.141 | 125 | 4/27/2009 1:36:09 AM | 43.86 | |
| 3 | 208.76.111.138 | 10 | 4/27/2009 6:03:14 AM | 03.51 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/135 - ms rpc | 58 | 4/27/2009 1:58:48 AM | 20.35 | |
| 2 | TCP/22 - ssh | 18 | 4/27/2009 3:42:56 PM | 06.32 | |
| 3 | TCP/16904 | 17 | 4/27/2009 2:34:08 AM | 05.96 | |
| 4 | TCP/2967 | 14 | 4/27/2009 9:02:22 AM | 04.91 | |
| 5 | TCP/1433 - ms sql | 12 | 4/27/2009 4:09:44 AM | 04.21 | |
| 6 | TCP/445 - netbios | 12 | 4/27/2009 9:41:15 AM | 04.21 | |
| 7 | UDP/1434 - ms sql monitor | 11 | 4/27/2009 2:01:41 AM | 03.86 | |
| 8 | UDP/137 - netbios | 08 | 4/27/2009 1:36:09 AM | 02.81 | |
| 9 | TCP/5900 - vnc | 08 | 4/27/2009 2:49:15 PM | 02.81 | |
| 10 | TCP/139 - netbios | 07 | 4/27/2009 9:53:40 AM | 02.46 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP flags SYN | 154 | 4/27/2009 1:56:11 AM | 54.04 | |
| 2 | TCP flags RST ACK | 57 | 4/27/2009 1:31:01 AM | 20.00 | |
| 3 | Firewall policy | 39 | 4/27/2009 1:36:09 AM | 13.68 | |
| 4 | TCP flags SYN ACK | 20 | 4/27/2009 2:34:08 AM | 07.02 | |
| 5 | Denied by ACL | 10 | 4/27/2009 6:03:14 AM | 03.51 | |
| 6 | Firewall policy | 04 | 4/27/2009 5:48:47 AM | 01.40 | |
| 7 | TCP flags RST | 01 | 4/27/2009 9:40:37 PM | 00.35 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/135 - ms rpc | TCP flags SYN | 58 | 20.35 | |
| 2 | TCP/16904 | TCP flags SYN ACK | 17 | 5.96 | |
| 3 | TCP/2967 | TCP flags SYN | 14 | 4.91 | |
| 4 | TCP/1433 - ms sql | TCP flags SYN | 12 | 4.21 | |
| 5 | TCP/445 - netbios | TCP flags SYN | 12 | 4.21 | |
| 6 | TCP/22 - ssh | TCP flags SYN | 12 | 4.21 | |
| 7 | UDP/1434 - ms sql monitor | Firewall policy | 11 | 3.86 | |
| 8 | UDP/137 - netbios | Firewall policy | 08 | 2.81 | |
| 9 | TCP/5900 - vnc | TCP flags SYN | 08 | 2.81 | |
| 10 | TCP/139 - netbios | TCP flags SYN | 07 | 2.46 |
Top 10 warning messages
| No | Source | Destination | Protocol | Warning | Count | First warning | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 192.168.25.15 | www.eventid.net (208.76.111.139) | TCP/0 | Bad TCP hdr length - 0 | 04 | 4/27/2009 2:41:42 AM | 80.00 | |
| 2 | 192.168.10.249 | www.eventid.net (208.76.111.139) | TCP/80 - http | Bad TCP hdr length - 80 | 01 | 4/27/2009 4:33:44 AM | 20.00 |
Firewall: 192.168.5.1 - Interfaces: Not specified - Go to top
Top 10 source, destination, protocol, URL messages
Top 10 urls and connections
Top 10 urls and connections
| No | URL | Connections | % | Comment | 1 | /images/ms_logo.gif | 81,265 | 13.43 | 2 | /css/evid_core.css | 34,405 | 05.69 | 3 | /lib/library.js | 33,891 | 05.60 | 4 | /images/header_bg_3.jpg | 33,883 | 05.60 | 5 | /images/top_page_bg_3.jpg | 33,597 | 05.55 | 6 | /images/footer_bg_3.jpg | 33,545 | 05.54 | 7 | /images/header_middle_bg_3.jpg | 33,537 | 05.54 | 8 | /images/bottom_page_bg_3.jpg | 33,487 | 05.53 | 9 | /images/evlogright.gif | 33,401 | 05.52 | 10 | /images/footer_middle_bg_3.jpg | 33,120 | 05.47 |
|---|
| No | Code | Message sample | Count | Comment |
|---|---|---|---|---|
| 1 | 4-411001 | Line protocol on Interface inside, changed state to up | 2 | |
| To assist us in improving the analyzer, please send the messages above to support@firegen.com and they will be added to the next release of Firegen. | ||||
Analysis details
| Analysis start time | 11/5/2011 11:51:54 AM |
| Analysis duration | 2.48 minutes (149 seconds) |
| Analysis engine version | Cisco Pix/ASA parser version: 0.12 FireGen30Service.exe - FireGen scheduler service: 3.0.0.0 |
| Filtering criteria | All entries |
| Excluded keywords | No connection |
Glossary
| !!! | Indicates that a high denials:connections ration has been detected. The current configured ratio is 3. The !!! indicates that the percentage of denials for that hour is bigger than 3 x the connections percentage. This indicates some unusual denial activity that may have to be investigated. The ratio can be configured on the Report Formats interface. |
| Other messages | The Other messages represents a list of message not yet configured in the Firegen parser. Please send these messages to us (support@firegen.com) and we will add them in the next Firegen update. These messages are included in the list of message types but they are not yet fully understood by the analyzer. |