FireGen Report
| Info | Value |
|---|---|
| Log profile | Log profile Netscreen |
| Analyzed log(s) |
F:\Logs\Sonicwall\09-29-2006-SyslogCatchAll.txt (76.00 MB) |
| Firewall type | Sonicwall |
| Analysis interval | All entries in the specified log |
Firewalls
| No | Firewall | Connections | Traffic (MB) | Denials | Warnings | URLs | 1 | 72.13.230.2 | 92,361 | 2,437.87 | 2,695 | 2,154 | 00 |
|---|
Message types
| No | Code | Message sample | Count | 2 | 1024 | msg="Connection Closed" n=47123 src=216.46.76.195:28378:X1:ip195.practicaltech.net dst=10.1.2.3:443:X0:STEMPSVR3 proto=tcp/443 sent=1129 rcvd=2316 | 92,361 | 3 | 10240 | msg="ICMP packet from LAN dropped" n=1079 src=10.1.2.14:137:X0 dst=10.1.2.1:1860:X0 type=3 code=3 | 485 | 4 | 1048576 | msg="VoIP 10.1.2.1 (H.323) Endpoint removed" n=4 | 06 | 5 | 128 | msg="UDP packet dropped" n=21919 src=192.168.20.250:514:X1 dst=10.1.2.4:514:X0:stempsvr4.stempsystems.local proto=udp/syslog | 645 | 6 | 16 | msg="SENDING>>>> ISAKMP OAK INFO (InitCookie:0x3adad5f46307a9b2 RespCookie:0x316153d959e741fb, MsgID: 0x4C75720) *(HASH, NOTIFY:DPD_ACK)" n=35973 src=72.13.230.2:500::2-230-13-72.cosmoweb.net dst=66.108.130.30:500::cpe-66-108-130-30.nyc.res.rr.com | 102,722 | 7 | 256 | msg="ICMP packet dropped" n=1824 src=10.1.46.253:3:X1 dst=10.1.2.1:3:X0 type=3 code=3 | 453 | 8 | 262144 | msg="Connection Opened" n=35397 src=10.1.2.8:2830:X0:STEMPVMPNETMON dst=10.24.64.4:53:X1:FHNTSVR2 proto=tcp/dns | 68,579 | 9 | 32 | msg="Probable port scan dropped" n=6 src=147.135.8.6:46486:X1 dst=72.13.230.2:33493:X1:2-230-13-72.cosmoweb.net | 15 | 10 | 448 | msg="IPSec (ESP) packet dropped" n=819 src=68.173.146.77:0:X1:cpe-68-173-146-77.nyc.res.rr.com dst=72.13.230.2:0:X1:2-230-13-72.cosmoweb.net | 01 | 11 | 512 | msg="Broadcast packet dropped" n=14137 src=61.159.15.2:3400:X1 dst=255.255.255.255 proto=udp/1434 | 2,898 | 12 | 6144 | msg="UDP packet from LAN dropped" n=93 src=10.1.2.20:137:X0 dst=10.1.2.1:137:X0 proto=0 | 47 | 13 | 64 | msg="TCP connection dropped" n=3836 src=216.46.76.195:33644:X1:ip195.practicaltech.net dst=72.13.230.43:443:X1:43-230-13-72.cosmoweb.net proto=tcp/443 | 417 | 14 | 640 | msg="Received ISAKMP packet destined to port 500, expected on floated port 4500" n=944 src=68.39.142.55:500::pcp04208994pcs.brick101.nj.comcast.net dst=72.13.230.2:500::2-230-13-72.cosmoweb.net | 527 |
|---|
Firewall: 72.13.230.2
72.13.230.2 - Traffic and denials per hour




| Hour | Traffic (MB) | % | Connections | % | Denials | % | |
|---|---|---|---|---|---|---|---|
| 00-01 | 118.00 | 4.86 | 8,064 | 8.48 | 242 | 8.98 | |
| 01-02 | 158.00 | 6.51 | 8,509 | 8.95 | 238 | 8.83 | |
| 02-03 | 91.00 | 3.76 | 7,793 | 8.20 | 227 | 8.42 | |
| 03-04 | 80.00 | 3.28 | 7,743 | 8.15 | 234 | 8.68 | |
| 04-05 | 90.00 | 3.71 | 7,806 | 8.21 | 237 | 8.79 | |
| 05-06 | 75.00 | 3.12 | 7,707 | 8.11 | 235 | 8.72 | |
| 06-07 | 1,042.00 | 42.76 | 8,858 | 9.32 | 242 | 8.98 | |
| 07-08 | 232.00 | 9.55 | 8,678 | 9.13 | 235 | 8.72 | |
| 08-09 | 105.00 | 4.31 | 8,202 | 8.63 | 233 | 8.65 | |
| 09-10 | 125.00 | 5.13 | 9,633 | 10.13 | 241 | 8.94 | |
| 10-11 | 238.00 | 9.80 | 8,149 | 8.57 | 226 | 8.39 | |
| 11-12 | 77.00 | 3.19 | 3,817 | 4.02 | 102 | 3.78 | |
| 12-13 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 13-14 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 14-15 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 15-16 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 16-17 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 17-18 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 18-19 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 19-20 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 20-21 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 21-22 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 22-23 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 23-24 | 00.00 | 0.01 | 97 | 0.10 | 03 | 0.11 |
72.13.230.2 - Interfaces
| No | Interfaces | Connections | MB | % | Denials | Warnings |
|---|---|---|---|---|---|---|
| 1 | X0 | 8,978 | 14.20 | 00.58 | 1,162 | 00 |
| 2 | X0 to X1 | 34,075 | 309.30 | 12.69 | 00 | 00 |
| 3 | X0 to X2 | 42 | 00.00 | 00.00 | 00 | 00 |
| 4 | X1 to X0 | 20,953 | 2,098.97 | 86.10 | 1,108 | 00 |
| 5 | X1 | 28,208 | 14.90 | 00.61 | 362 | 00 |
| 6 | X2 to X0 | 93 | 00.49 | 00.02 | 06 | 00 |
| 7 | X2 | 12 | 00.01 | 00.00 | 54 | 00 |
| 8 | X1 to | 00 | 00.00 | 00.00 | 03 | 00 |
| 9 | Not specified | 00 | 00.00 | 00.00 | 00 | 2,154 |
| Total | 92,361 | 2,437.87 | 2,695 | 2,154 |
Firewall: 72.13.230.2 - Interface: X0 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.2.50 | 13,051,860 | 87.64 | |
| 2 | 10.1.2.1 | 1,570,680 | 10.55 | |
| 3 | 10.1.2.5 | 147,475 | 0.99 | |
| 4 | 10.1.2.8 | 121,822 | 0.82 | 257 denials recorded on 9/29/2006 12:00:55 AM |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.2.1 | 13,051,860 | 87.64 | |
| 2 | 10.1.2.3 | 887,519 | 5.96 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 3 | 10.1.2.5 | 826,039 | 5.55 | |
| 4 | 10.1.2.14 | 37,128 | 0.25 | 403 denials recorded on 9/29/2006 12:04:40 AM |
| 5 | 10.1.2.155 | 9,042 | 0.06 | |
| 6 | 10.1.2.213 | 6,974 | 0.05 | |
| 7 | 10.1.2.171 | 6,240 | 0.04 | |
| 8 | 10.1.2.132 | 5,538 | 0.04 | |
| 9 | 10.1.2.43 | 5,194 | 0.03 | |
| 10 | 10.1.2.168 | 4,992 | 0.03 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.1.2.50 | HTTP | 1,166 | 13,026,454 | 87.47 | |
| 2 | 10.1.2.1 | DNS | 6,678 | 1,435,347 | 9.64 | |
| 3 | 10.1.2.5 | TCP/443 - ssl-https | 12 | 146,396 | 0.98 | |
| 4 | 10.1.2.1 | NETBIOS-NS | 1,004 | 134,891 | 0.91 | |
| 5 | 10.1.2.8 | HTTP | 101 | 121,822 | 0.82 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 6 | 10.1.2.50 | HTTP | 09 | 23,980 | 0.16 | |
| 7 | 10.1.2.50 | HTTP | 05 | 1,426 | 0.01 | |
| 8 | 10.1.2.5 | HTTP | 01 | 1,079 | 0.01 | |
| 9 | 10.1.2.1 | UDP/1719 | 02 | 442 | 0.00 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.1.2.50 | 10.1.2.1 | HTTP | 1,166 | 13,026,454 | 87.47 | |
| 2 | 10.1.2.1 | 10.1.2.3 | DNS | 3,339 | 735,376 | 4.94 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 3 | 10.1.2.1 | 10.1.2.5 | DNS | 3,339 | 699,971 | 4.70 | |
| 4 | 10.1.2.5 | 10.1.2.3 | TCP/443 - ssl-https | 12 | 146,396 | 0.98 | |
| 5 | 10.1.2.8 | 10.1.2.5 | HTTP | 101 | 121,822 | 0.82 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 6 | 10.1.2.1 | 10.1.2.14 | NETBIOS-NS | 476 | 37,128 | 0.25 | 403 denials recorded on 9/29/2006 12:04:40 AM |
| 7 | 10.1.2.50 | 10.1.2.1 | HTTP | 09 | 23,980 | 0.16 | |
| 8 | 10.1.2.1 | 10.1.2.155 | NETBIOS-NS | 30 | 9,042 | 0.06 | |
| 9 | 10.1.2.1 | 10.1.2.213 | NETBIOS-NS | 22 | 6,974 | 0.05 | |
| 10 | 10.1.2.1 | 10.1.2.171 | NETBIOS-NS | 80 | 6,240 | 0.04 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP OP=GET | 1,268 | 13,149,355 | 88.30 | |
| 2 | DNS | 6,678 | 1,435,347 | 9.64 | |
| 3 | TCP/443 - ssl-https | 12 | 146,396 | 0.98 | |
| 4 | NETBIOS-NS | 1,004 | 134,891 | 0.91 | |
| 5 | HTTP OP=POST | 09 | 23,980 | 0.16 | |
| 6 | HTTP | 05 | 1,426 | 0.01 | |
| 7 | UDP/1719 | 02 | 442 | 0.00 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.2.14 | 403 | 9/29/2006 12:04:40 AM | 34.68 | 403 denials recorded on 9/29/2006 12:04:40 AM |
| 2 | 10.1.2.8 | 257 | 9/29/2006 12:00:55 AM | 22.12 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 3 | 10.1.2.3 | 170 | 9/29/2006 12:10:36 AM | 14.63 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 4 | 10.1.2.213 | 86 | 9/29/2006 12:03:09 AM | 07.40 | |
| 5 | 10.1.2.54 | 60 | 9/29/2006 1:14:52 AM | 05.16 | |
| 6 | 10.1.2.171 | 29 | 9/29/2006 12:01:54 AM | 02.50 | |
| 7 | 10.1.2.132 | 27 | 9/29/2006 12:44:09 AM | 02.32 | |
| 8 | 10.1.2.168 | 17 | 9/29/2006 12:09:25 AM | 01.46 | |
| 9 | 10.1.2.155 | 11 | 9/29/2006 12:29:55 AM | 00.95 | |
| 10 | 10.1.2.42 | 09 | 9/29/2006 1:09:24 AM | 00.77 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.2.1 | 532 | 9/29/2006 12:01:54 AM | 45.78 | |
| 2 | 10.1.2.255 | 407 | 9/29/2006 12:00:55 AM | 35.03 | |
| 3 | Broadcast | 223 | 9/29/2006 12:10:36 AM | 19.19 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP/3 - unreach | 485 | 9/29/2006 12:01:54 AM | 41.74 | |
| 2 | NETBIOS-NS | 250 | 9/29/2006 12:00:55 AM | 21.51 | |
| 3 | NETBIOS-DGM | 157 | 9/29/2006 12:03:09 AM | 13.51 | |
| 4 | UDP/1266 | 122 | 9/29/2006 12:10:36 AM | 10.50 | |
| 5 | UDP/5000 | 56 | 9/29/2006 9:41:08 AM | 04.82 | |
| 6 | UDP/161 - snmp | 42 | 9/29/2006 12:14:10 AM | 03.61 | |
| 7 | UDP/20046 - network probe | 39 | 9/29/2006 1:22:17 AM | 03.36 | |
| 8 | UDP/58085 | 06 | 9/29/2006 12:19:03 AM | 00.52 | |
| 9 | UDP/137 - netbios | 04 | 9/29/2006 7:00:13 AM | 00.34 | |
| 10 | UDP/1900 - univ. plug-and-play | 01 | 9/29/2006 12:48:20 AM | 00.09 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | Broadcast packet dropped | 630 | 9/29/2006 12:00:55 AM | 54.22 | |
| 2 | ICMP packet from LAN dropped | 485 | 9/29/2006 12:01:54 AM | 41.74 | |
| 3 | UDP packet from LAN dropped | 47 | 9/29/2006 12:14:10 AM | 04.04 |

Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 10.1.2.14 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet from LAN dropped | 403 | 9/29/2006 12:04:40 AM | 34.68 | 403 denials recorded on 9/29/2006 12:04:40 AM |
| 2 | 10.1.2.8 | 10.1.2.255 | NETBIOS-NS | Broadcast packet dropped | 211 | 9/29/2006 12:00:55 AM | 18.16 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 3 | 10.1.2.3 | Broadcast | UDP/1266 | Broadcast packet dropped | 122 | 9/29/2006 12:10:36 AM | 10.50 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 4 | 10.1.2.213 | 10.1.2.255 | NETBIOS-DGM | Broadcast packet dropped | 86 | 9/29/2006 12:03:09 AM | 7.40 | |
| 5 | 10.1.2.54 | Broadcast | UDP/5000 | Broadcast packet dropped | 56 | 9/29/2006 9:41:08 AM | 4.82 | |
| 6 | 10.1.2.8 | 10.1.2.1 | UDP/161 - snmp | UDP packet from LAN dropped | 42 | 9/29/2006 12:14:10 AM | 3.61 | |
| 7 | 10.1.2.3 | Broadcast | UDP/20046 - network probe | Broadcast packet dropped | 39 | 9/29/2006 1:22:17 AM | 3.36 | |
| 8 | 10.1.2.171 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet from LAN dropped | 29 | 9/29/2006 12:01:54 AM | 2.50 | |
| 9 | 10.1.2.132 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet from LAN dropped | 27 | 9/29/2006 12:44:09 AM | 2.32 | |
| 10 | 10.1.2.168 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet from LAN dropped | 17 | 9/29/2006 12:09:25 AM | 1.46 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP/3 - unreach | ICMP packet from LAN dropped | 485 | 41.74 | |
| 2 | NETBIOS-NS | Broadcast packet dropped | 250 | 21.51 | |
| 3 | NETBIOS-DGM | Broadcast packet dropped | 157 | 13.51 | |
| 4 | UDP/1266 | Broadcast packet dropped | 122 | 10.50 | |
| 5 | UDP/5000 | Broadcast packet dropped | 56 | 4.82 | |
| 6 | UDP/161 - snmp | UDP packet from LAN dropped | 42 | 3.61 | |
| 7 | UDP/20046 - network probe | Broadcast packet dropped | 39 | 3.36 | |
| 8 | UDP/58085 | Broadcast packet dropped | 06 | 0.52 | |
| 9 | UDP/137 - netbios | UDP packet from LAN dropped | 04 | 0.34 | |
| 10 | UDP/1900 - univ. plug-and-play | UDP packet from LAN dropped | 01 | 0.09 |
Firewall: 72.13.230.2 - Interfaces: X0 to X1 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.2.5 | 104,489,271 | 32.22 | |
| 2 | 10.1.2.8 | 62,992,316 | 19.42 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 3 | 10.1.2.50 | 54,413,734 | 16.78 | |
| 4 | 10.1.2.42 | 36,551,043 | 11.27 | |
| 5 | 10.1.2.54 | 28,577,744 | 8.81 | |
| 6 | 10.1.2.168 | 21,997,459 | 6.78 | |
| 7 | 10.1.2.60 | 5,089,743 | 1.57 | |
| 8 | 10.1.2.161 | 4,350,002 | 1.34 | |
| 9 | 10.1.2.3 | 2,166,296 | 0.67 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 10 | 10.1.2.132 | 1,175,048 | 0.36 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | ip67-93-135-175.z135-93-67.customer.algx.net (67.93.135.175) | 83,990,103 | 25.90 | |
| 2 | 192.168.20.1 | 22,339,285 | 6.89 | |
| 3 | 147.135.0.128 | 21,955,588 | 6.77 | |
| 4 | 10.24.64.4 | 17,440,385 | 5.38 | |
| 5 | 172.20.4.101 | 14,964,169 | 4.61 | |
| 6 | 10.1.13.2 | 12,380,696 | 3.82 | |
| 7 | www.xs4all.nl (194.109.6.92) | 11,830,458 | 3.65 | |
| 8 | mailserver-druckzentrum.de (80.190.240.92) | 10,772,279 | 3.32 | |
| 9 | 192.168.20.4 | 10,355,147 | 3.19 | |
| 10 | xml02.good.com (216.136.156.86) | 6,873,312 | 2.12 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.1.2.5 | HTTP | 32 | 86,451,832 | 26.66 | |
| 2 | 10.1.2.50 | TCP/6129 - agobot-worm | 20 | 47,943,456 | 14.78 | |
| 3 | 10.1.2.8 | UDP/161 - snmp | 6,781 | 45,403,098 | 14.00 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 4 | 10.1.2.42 | HTTP | 1,078 | 35,037,575 | 10.80 | |
| 5 | 10.1.2.54 | TCP/6129 - agobot-worm | 05 | 27,198,405 | 8.39 | |
| 6 | 10.1.2.168 | UDP/14842 | 01 | 21,412,332 | 6.60 | |
| 7 | 10.1.2.5 | TCP/443 - ssl-https | 114 | 17,289,947 | 5.33 | |
| 8 | 10.1.2.8 | TCP/1351 | 153 | 6,847,870 | 2.11 | |
| 9 | 10.1.2.50 | TCP/443 - ssl-https | 657 | 5,023,932 | 1.55 | |
| 10 | 10.1.2.60 | TCP/6129 - agobot-worm | 07 | 4,575,520 | 1.41 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.1.2.5 | ip67-93-135-175.z135-93-67.customer.algx.net (67.93.135.175) | HTTP | 19 | 83,921,322 | 25.88 | |
| 2 | 10.1.2.54 | 192.168.20.1 | TCP/6129 - agobot-worm | 03 | 22,270,280 | 6.87 | |
| 3 | 10.1.2.168 | 147.135.0.128 | UDP/14842 | 01 | 21,412,332 | 6.60 | |
| 4 | 10.1.2.50 | 10.24.64.4 | TCP/6129 - agobot-worm | 01 | 16,711,340 | 5.15 | |
| 5 | 10.1.2.50 | 172.20.4.101 | TCP/6129 - agobot-worm | 01 | 14,963,870 | 4.61 | |
| 6 | 10.1.2.42 | www.xs4all.nl (194.109.6.92) | HTTP | 21 | 11,830,458 | 3.65 | |
| 7 | 10.1.2.42 | mailserver-druckzentrum.de (80.190.240.92) | HTTP | 01 | 10,767,801 | 3.32 | |
| 8 | 10.1.2.50 | 192.168.20.4 | TCP/6129 - agobot-worm | 01 | 8,501,057 | 2.62 | |
| 9 | 10.1.2.5 | xml02.good.com (216.136.156.86) | TCP/443 - ssl-https | 20 | 6,873,312 | 2.12 | |
| 10 | 10.1.2.8 | 10.1.13.2 | TCP/1351 | 153 | 6,847,870 | 2.11 | 257 denials recorded on 9/29/2006 12:00:55 AM |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP OP=GET | 1,528 | 126,934,769 | 39.14 | |
| 2 | TCP/6129 - agobot-worm | 33 | 80,456,876 | 24.81 | |
| 3 | UDP/161 - snmp | 6,781 | 45,403,098 | 14.00 | |
| 4 | TCP/443 - ssl-https | 1,302 | 26,608,350 | 8.20 | |
| 5 | UDP/14842 | 01 | 21,412,332 | 6.60 | |
| 6 | TCP/1351 | 153 | 6,847,870 | 2.11 | |
| 7 | NETBIOS-NS | 8,948 | 3,533,100 | 1.09 | |
| 8 | DNS | 7,739 | 2,965,333 | 0.91 | |
| 9 | TCP/1356 | 62 | 2,754,790 | 0.85 | |
| 10 | TCP/1796 | 258 | 2,450,820 | 0.76 |

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.2.50 | ip-66-80-255-195.nyc.megapath.net (66.80.255.195) | 01 | 212,094 | |
| 2 | 10.1.2.50 | 10.1.46.2 | 01 | 209,339 | |
| 3 | 10.1.2.42 | 10.1.47.124 | 01 | 94,028 | |
| 4 | 10.1.2.50 | ip-216-36-121-234.dsl.nyc.megapath.net (216.36.121.234) | 01 | 56,009 | |
| 5 | 10.1.2.50 | 192.168.1.3 | 01 | 48,346 | 15139 denials recorded on 4/3/2006 11:01:31 PM |
| 6 | 10.1.2.50 | 192.168.1.6 | 06 | 528 | |
| 7 | 10.1.2.50 | 172.20.4.31 | 01 | 435 | |
| 8 | 10.1.2.50 | 192.168.1.4 | 03 | 264 | |
| 9 | 10.1.2.50 | 10.1.46.4 | 03 | 264 | |
| 10 | 10.1.2.50 | 10.1.46.3 | 01 | 96 |
Firewall: 72.13.230.2 - Interfaces: X0 to X2 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.2.3 | 1,794 | 88.46 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 2 | 10.1.2.1 | 234 | 11.54 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | 1,656 | 81.66 | |
| 2 | 10.1.72.2 | 372 | 18.34 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 10.1.2.3 | UDP/1049 | 36 | 1,656 | 81.66 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 2 | 10.1.2.1 | NETBIOS-NS | 03 | 234 | 11.54 | |
| 3 | 10.1.2.3 | UDP/2872 | 03 | 138 | 6.80 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 10.1.2.3 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | UDP/1049 | 36 | 1,656 | 81.66 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 2 | 10.1.2.1 | 10.1.72.2 | NETBIOS-NS | 03 | 234 | 11.54 | |
| 3 | 10.1.2.3 | 10.1.72.2 | UDP/2872 | 03 | 138 | 6.80 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/1049 | 36 | 1,656 | 81.66 | |
| 2 | NETBIOS-NS | 03 | 234 | 11.54 | |
| 3 | UDP/2872 | 03 | 138 | 6.80 |

Firewall: 72.13.230.2 - Interfaces: X1 to X0 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | ool-18b88aae.dyn.optonline.net (24.184.138.174) | 1,003,489,464 | 45.59 | |
| 2 | 10.110.2.50 | 857,286,851 | 38.95 | |
| 3 | ip-69-33-141-98.nyc.megapath.net (69.33.141.98) | 252,069,240 | 11.45 | |
| 4 | 64-6-187-66.t1.nyc.megapath.net (64.6.187.66) | 32,843,695 | 1.49 | |
| 5 | 10.100.2.100 | 17,527,884 | 0.80 | |
| 6 | 10.100.2.50 | 5,907,312 | 0.27 | |
| 7 | 10.110.2.100 | 3,660,346 | 0.17 | |
| 8 | yahoo-wildcard.a05.yahoodns.net (66.218.94.151) | 3,610,578 | 0.16 | |
| 9 | cpe-24-193-35-150.nyc.res.rr.com (24.193.35.150) | 3,525,411 | 0.16 | |
| 10 | 10.111.2.50 | 3,375,616 | 0.15 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.2.54 | 1,004,387,546 | 45.63 | |
| 2 | 10.1.2.3 | 817,611,330 | 37.15 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 3 | 10.1.2.14 | 258,370,212 | 11.74 | 403 denials recorded on 9/29/2006 12:04:40 AM |
| 4 | 10.1.2.50 | 114,465,124 | 5.20 | |
| 5 | 10.1.2.161 | 901,992 | 0.04 | |
| 6 | 10.1.2.77 | 900,494 | 0.04 | |
| 7 | 10.1.2.43 | 898,524 | 0.04 | |
| 8 | 10.1.2.51 | 898,314 | 0.04 | |
| 9 | 10.1.2.56 | 894,540 | 0.04 | |
| 10 | 10.1.2.53 | 890,054 | 0.04 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | ool-18b88aae.dyn.optonline.net (24.184.138.174) | TCP/3389 - ms rdp | 02 | 1,003,489,464 | 45.59 | |
| 2 | 10.110.2.50 | TCP/4000 | 253 | 725,774,450 | 32.98 | |
| 3 | ip-69-33-141-98.nyc.megapath.net (69.33.141.98) | SYSLOG | 244 | 252,069,240 | 11.45 | |
| 4 | 10.110.2.50 | TCP/3389 - ms rdp | 02 | 131,102,231 | 5.96 | |
| 5 | 64-6-187-66.t1.nyc.megapath.net (64.6.187.66) | SMTP | 04 | 32,843,695 | 1.49 | |
| 6 | 10.100.2.100 | TCP/4000 | 276 | 9,587,724 | 0.44 | |
| 7 | 10.100.2.100 | TCP/135 - ms rpc | 5,574 | 7,224,640 | 0.33 | |
| 8 | 10.100.2.50 | TCP/4000 | 262 | 4,795,362 | 0.22 | |
| 9 | yahoo-wildcard.a05.yahoodns.net (66.218.94.151) | SMTP | 01 | 3,610,578 | 0.16 | |
| 10 | cpe-24-193-35-150.nyc.res.rr.com (24.193.35.150) | SYSLOG | 51 | 3,525,411 | 0.16 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | ool-18b88aae.dyn.optonline.net (24.184.138.174) | 10.1.2.54 | TCP/3389 - ms rdp | 02 | 1,003,489,464 | 45.59 | |
| 2 | 10.110.2.50 | 10.1.2.3 | TCP/4000 | 253 | 725,774,450 | 32.98 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 3 | ip-69-33-141-98.nyc.megapath.net (69.33.141.98) | 10.1.2.14 | SYSLOG | 244 | 252,069,240 | 11.45 | 403 denials recorded on 9/29/2006 12:04:40 AM |
| 4 | 10.110.2.50 | 10.1.2.50 | TCP/3389 - ms rdp | 01 | 113,554,640 | 5.16 | |
| 5 | 64-6-187-66.t1.nyc.megapath.net (64.6.187.66) | 10.1.2.3 | SMTP | 04 | 32,843,695 | 1.49 | |
| 6 | 10.110.2.50 | 10.1.2.3 | TCP/3389 - ms rdp | 01 | 17,547,591 | 0.80 | |
| 7 | 10.100.2.100 | 10.1.2.3 | TCP/4000 | 276 | 9,587,724 | 0.44 | |
| 8 | 10.100.2.50 | 10.1.2.3 | TCP/4000 | 262 | 4,795,362 | 0.22 | |
| 9 | yahoo-wildcard.a05.yahoodns.net (66.218.94.151) | 10.1.2.3 | SMTP | 01 | 3,610,578 | 0.16 | |
| 10 | cpe-24-193-35-150.nyc.res.rr.com (24.193.35.150) | 10.1.2.14 | SYSLOG | 51 | 3,525,411 | 0.16 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/3389 - ms rdp | 04 | 1,134,591,695 | 51.55 | |
| 2 | TCP/4000 | 2,363 | 748,950,880 | 34.03 | |
| 3 | SYSLOG | 829 | 258,362,112 | 11.74 | |
| 4 | SMTP | 517 | 42,568,149 | 1.93 | |
| 5 | TCP/135 - ms rpc | 5,615 | 7,275,696 | 0.33 | |
| 6 | TCP/4003 | 3,474 | 3,658,080 | 0.17 | |
| 7 | TCP/1433 - ms sql | 4,654 | 3,072,162 | 0.14 | |
| 8 | TCP/443 - ssl-https | 499 | 934,203 | 0.04 | |
| 9 | HTTP OP=GET | 32 | 832,538 | 0.04 | |
| 10 | TCP/1984 - big brother | 2,050 | 192,700 | 0.01 |

Top 10 protocol TCP/3389 - ms rdp: Sources, destinations, and traffic
| No | Source | Destination | Connections | Bytes | Comment |
|---|---|---|---|---|---|
| 1 | ool-18b88aae.dyn.optonline.net (24.184.138.174) | 10.1.2.54 | 02 | 1,003,489,464 | |
| 2 | 10.110.2.50 | 10.1.2.50 | 01 | 113,554,640 | |
| 3 | 10.110.2.50 | 10.1.2.3 | 01 | 17,547,591 | 170 denials recorded on 9/29/2006 12:10:36 AM |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 192.168.20.250 | 501 | 9/29/2006 12:00:49 AM | 45.22 | 501 denials recorded on 9/29/2006 12:00:49 AM |
| 2 | 10.3.64.1 | 165 | 9/29/2006 12:06:36 AM | 14.89 | 165 denials recorded on 9/29/2006 12:06:36 AM |
| 3 | 10.1.11.15 | 53 | 9/29/2006 12:07:39 AM | 04.78 | 53 denials recorded on 9/29/2006 12:07:39 AM |
| 4 | 10.2.64.1 | 41 | 9/29/2006 12:29:42 AM | 03.70 | |
| 5 | 10.1.13.3 | 31 | 9/29/2006 12:14:11 AM | 02.80 | |
| 6 | 10.1.13.184 | 28 | 9/29/2006 8:44:25 AM | 02.53 | |
| 7 | 192.168.101.132 | 27 | 9/29/2006 12:21:47 AM | 02.44 | |
| 8 | 146.203.230.1 | 26 | 9/29/2006 12:04:28 AM | 02.35 | |
| 9 | 10.1.60.1 | 24 | 9/29/2006 12:02:17 AM | 02.17 | |
| 10 | 10.1.30.1 | 24 | 9/29/2006 12:46:53 AM | 02.17 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.2.4 | 589 | 9/29/2006 12:00:49 AM | 53.16 | |
| 2 | 10.1.2.1 | 339 | 9/29/2006 12:00:45 AM | 30.60 | |
| 3 | 10.1.2.3 | 77 | 9/29/2006 12:21:47 AM | 06.95 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 4 | 10.1.2.8 | 59 | 9/29/2006 12:07:39 AM | 05.32 | 257 denials recorded on 9/29/2006 12:00:55 AM |
| 5 | 10.1.2.5 | 24 | 9/29/2006 1:53:07 AM | 02.17 | |
| 6 | 10.1.2.50 | 06 | 9/29/2006 12:08:58 AM | 00.54 | |
| 7 | 10.1.2.119 | 04 | 9/29/2006 12:11:19 AM | 00.36 | |
| 8 | 10.1.2.42 | 03 | 9/29/2006 7:10:42 AM | 00.27 | |
| 9 | 10.1.2.54 | 02 | 9/29/2006 12:36:55 AM | 00.18 | |
| 10 | 10.1.2.59 | 01 | 9/29/2006 1:15:08 AM | 00.09 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/514 - syslog | 589 | 9/29/2006 12:00:49 AM | 53.16 | |
| 2 | ICMP/3 - unreach | 390 | 9/29/2006 12:00:45 AM | 35.20 | |
| 3 | UDP/53 - dns | 27 | 9/29/2006 12:21:47 AM | 02.44 | |
| 4 | TCP/80 - http | 26 | 9/29/2006 8:14:21 AM | 02.35 | |
| 5 | TCP/25 - smtp | 11 | 9/29/2006 1:13:00 AM | 00.99 | |
| 6 | TCP/445 - netbios | 10 | 9/29/2006 4:01:44 AM | 00.90 | |
| 7 | UDP/162 - snmp-trap | 07 | 9/29/2006 2:22:13 AM | 00.63 | |
| 8 | TCP/11677 | 05 | 9/29/2006 3:59:47 AM | 00.45 | |
| 9 | UDP/2967 - symantec-av | 04 | 9/29/2006 12:11:19 AM | 00.36 | |
| 10 | TCP/1433 - ms sql | 04 | 9/29/2006 1:15:08 AM | 00.36 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP packet dropped | 627 | 9/29/2006 12:00:49 AM | 56.59 | |
| 2 | ICMP packet dropped | 395 | 9/29/2006 12:00:45 AM | 35.65 | |
| 3 | TCP connection dropped | 60 | 9/29/2006 12:36:55 AM | 05.42 | |
| 4 | Web access request dropped | 26 | 9/29/2006 8:14:21 AM | 02.35 |

Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 192.168.20.250 | 10.1.2.4 | UDP/514 - syslog | UDP packet dropped | 501 | 9/29/2006 12:00:49 AM | 45.22 | 501 denials recorded on 9/29/2006 12:00:49 AM |
| 2 | 10.3.64.1 | 10.1.2.4 | UDP/514 - syslog | UDP packet dropped | 88 | 9/29/2006 12:07:06 AM | 7.94 | 165 denials recorded on 9/29/2006 12:06:36 AM |
| 3 | 10.3.64.1 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet dropped | 77 | 9/29/2006 12:06:36 AM | 6.95 | |
| 4 | 10.1.11.15 | 10.1.2.8 | ICMP/3 - unreach | ICMP packet dropped | 47 | 9/29/2006 12:07:39 AM | 4.24 | 257 denials recorded on 9/29/2006 12:00:55 AM 257 denials recorded on 9/29/2006 12:00:55 AM 53 denials recorded on 9/29/2006 12:07:39 AM |
| 5 | 10.2.64.1 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet dropped | 41 | 9/29/2006 12:29:42 AM | 3.70 | |
| 6 | 10.1.13.3 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet dropped | 31 | 9/29/2006 12:14:11 AM | 2.80 | |
| 7 | 192.168.101.132 | 10.1.2.3 | UDP/53 - dns | UDP packet dropped | 27 | 9/29/2006 12:21:47 AM | 2.44 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 8 | 146.203.230.1 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet dropped | 26 | 9/29/2006 12:04:28 AM | 2.35 | |
| 9 | 10.1.60.1 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet dropped | 24 | 9/29/2006 12:02:17 AM | 2.17 | |
| 10 | 10.1.30.1 | 10.1.2.1 | ICMP/3 - unreach | ICMP packet dropped | 24 | 9/29/2006 12:46:53 AM | 2.17 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/514 - syslog | UDP packet dropped | 589 | 53.16 | |
| 2 | ICMP/3 - unreach | ICMP packet dropped | 390 | 35.20 | |
| 3 | UDP/53 - dns | UDP packet dropped | 27 | 2.44 | |
| 4 | TCP/80 - http | Web access request dropped | 26 | 2.35 | |
| 5 | TCP/25 - smtp | TCP connection dropped | 11 | 0.99 | |
| 6 | TCP/445 - netbios | TCP connection dropped | 10 | 0.90 | |
| 7 | UDP/162 - snmp-trap | UDP packet dropped | 07 | 0.63 | |
| 8 | TCP/11677 | TCP connection dropped | 05 | 0.45 | |
| 9 | UDP/2967 - symantec-av | UDP packet dropped | 04 | 0.36 | |
| 10 | TCP/1433 - ms sql | TCP connection dropped | 04 | 0.36 |
Firewall: 72.13.230.2 - Interface: X1 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | ool-18b88aae.dyn.optonline.net (24.184.138.174) | 7,747,856 | 49.60 | |
| 2 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | 5,161,488 | 33.04 | |
| 3 | c-68-39-142-55.hsd1.nj.comcast.net (68.39.142.55) | 290,088 | 1.86 | |
| 4 | 43-248-234-66.static.cosmoweb.net (66.234.248.43) | 287,668 | 1.84 | |
| 5 | adsl-66-139-44-124.dsl.tulsok.swbell.net (66.139.44.124) | 282,768 | 1.81 | |
| 6 | p84-114.acedsl.com (66.114.84.114) | 156,448 | 1.00 | |
| 7 | mail.mikam.com (216.46.84.195) | 156,344 | 1.00 | |
| 8 | ool-182fc26b.dyn.optonline.net (24.47.194.107) | 156,316 | 1.00 | |
| 9 | cpe-66-108-130-30.nyc.res.rr.com (66.108.130.30) | 156,140 | 1.00 | |
| 10 | cpe-24-193-35-150.nyc.res.rr.com (24.193.35.150) | 155,948 | 1.00 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | 10,460,158 | 66.96 | |
| 2 | v997.core1.ash1.he.net (216.66.37.13) | 3,392,700 | 21.72 | |
| 3 | pool-141-155-152-168.ny5030.east.verizon.net (141.155.152.168) | 570,920 | 3.65 | |
| 4 | c-67-172-11-40.hsd1.in.comcast.net (67.172.11.40) | 460,580 | 2.95 | |
| 5 | 8.4.112.74 | 215,908 | 1.38 | |
| 6 | 64.41.135.42 | 130,020 | 0.83 | |
| 7 | 218.1.128.249 | 48,106 | 0.31 | |
| 8 | 147.135.0.7 | 19,582 | 0.13 | |
| 9 | 68.166.102.202 | 14,520 | 0.09 | |
| 10 | moon.cosmoweb.net (66.234.224.3) | 12,687 | 0.08 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | ool-18b88aae.dyn.optonline.net (24.184.138.174) | TCP/9000 | 817 | 7,747,856 | 49.60 | |
| 2 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | DNS | 15,258 | 3,624,804 | 23.20 | |
| 3 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | UDP/500 - ipsec | 623 | 1,211,684 | 7.76 | |
| 4 | c-68-39-142-55.hsd1.nj.comcast.net (68.39.142.55) | UDP/4500 - vpn client | 528 | 290,088 | 1.86 | |
| 5 | 43-248-234-66.static.cosmoweb.net (66.234.248.43) | UDP/500 - ipsec | 679 | 287,668 | 1.84 | |
| 6 | adsl-66-139-44-124.dsl.tulsok.swbell.net (66.139.44.124) | UDP/500 - ipsec | 669 | 282,768 | 1.81 | |
| 7 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | NETBIOS-NS | 1,625 | 192,188 | 1.23 | |
| 8 | p84-114.acedsl.com (66.114.84.114) | UDP/500 - ipsec | 677 | 156,448 | 1.00 | |
| 9 | mail.mikam.com (216.46.84.195) | UDP/500 - ipsec | 679 | 156,344 | 1.00 | |
| 10 | ool-182fc26b.dyn.optonline.net (24.47.194.107) | UDP/500 - ipsec | 679 | 156,316 | 1.00 |
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/9000 | 817 | 7,747,856 | 49.60 | |
| 2 | UDP/500 - ipsec | 9,864 | 3,629,758 | 23.24 | |
| 3 | DNS | 15,258 | 3,624,804 | 23.20 | |
| 4 | UDP/4500 - vpn client | 528 | 290,088 | 1.86 | |
| 5 | NETBIOS-NS | 1,625 | 192,188 | 1.23 | |
| 6 | TCP/443 - ssl-https | 11 | 129,942 | 0.83 | |
| 7 | HTTP | 90 | 4,140 | 0.03 | |
| 8 | NTP | 12 | 1,748 | 0.01 | |
| 9 | HTTP OP=GET | 01 | 634 | 0.00 | |
| 10 | UDP/1719 | 02 | 488 | 0.00 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ip-216-46-76-195.dsl.nyc.megapath.net (216.46.76.195) | 202 | 9/29/2006 12:01:59 AM | 55.80 | 202 denials recorded on 9/29/2006 12:01:59 AM |
| 2 | 209.150.98.78 | 42 | 9/29/2006 12:22:03 AM | 11.60 | 42 denials recorded on 9/29/2006 12:22:03 AM |
| 3 | ps3-img.us.dell.com (143.166.224.238) | 07 | 9/29/2006 9:05:53 AM | 01.93 | 7 denials recorded on 9/29/2006 9:05:53 AM |
| 4 | 8.4.112.100 | 05 | 9/29/2006 1:10:13 AM | 01.38 | |
| 5 | h228.62.16.72.dynamic.ip.windstream.net (72.16.62.228) | 05 | 9/29/2006 2:05:49 AM | 01.38 | |
| 6 | 211.147.224.237 | 05 | 9/29/2006 4:19:19 AM | 01.38 | |
| 7 | 147.135.20.6 | 05 | 9/29/2006 6:42:59 AM | 01.38 | |
| 8 | 194.109.22.135 | 05 | 9/29/2006 7:14:42 AM | 01.38 | |
| 9 | ge-16-1-cdnt01.brick1.nj.panjde.comcast.net (68.86.221.90) | 04 | 9/29/2006 12:10:31 AM | 01.10 | |
| 10 | 147.135.0.19 | 04 | 9/29/2006 1:27:14 AM | 01.10 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | mail.stempsystems.com (72.13.230.43) | 234 | 9/29/2006 12:00:05 AM | 64.64 | |
| 2 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | 98 | 9/29/2006 12:10:31 AM | 27.07 | |
| 3 | 45-230-13-72.static.cosmoweb.net (72.13.230.45) | 07 | 9/29/2006 5:59:09 AM | 01.93 | |
| 4 | Broadcast | 06 | 9/29/2006 12:55:25 AM | 01.66 | |
| 5 | 44-230-13-72.static.cosmoweb.net (72.13.230.44) | 04 | 9/29/2006 2:15:38 AM | 01.10 | |
| 6 | mail.stempsystems.com (72.13.230.49) | 03 | 9/29/2006 12:04:26 AM | 00.83 | |
| 7 | 50-230-13-72.static.cosmoweb.net (72.13.230.50) | 03 | 9/29/2006 1:16:37 AM | 00.83 | |
| 8 | 54-230-13-72.static.cosmoweb.net (72.13.230.54) | 02 | 9/29/2006 4:21:05 AM | 00.55 | |
| 9 | 57-230-13-72.static.cosmoweb.net (72.13.230.57) | 01 | 9/29/2006 12:29:11 AM | 00.28 | |
| 10 | v997.core1.ash1.he.net (216.66.37.13) | 01 | 9/29/2006 2:06:38 AM | 00.28 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | 202 | 9/29/2006 12:01:59 AM | 55.80 | |
| 2 | ICMP/3 - unreach | 42 | 9/29/2006 12:22:03 AM | 11.60 | |
| 3 | TCP/25 - smtp | 31 | 9/29/2006 12:00:05 AM | 08.56 | |
| 4 | UDP/33438 | 05 | 9/29/2006 1:27:14 AM | 01.38 | |
| 5 | ICMP/13 | 05 | 9/29/2006 1:44:53 AM | 01.38 | |
| 6 | TCP/15221 | 05 | 9/29/2006 7:14:42 AM | 01.38 | |
| 7 | ICMP/1 | 04 | 9/29/2006 12:10:31 AM | 01.10 | |
| 8 | ICMP/0 | 04 | 9/29/2006 12:50:45 AM | 01.10 | |
| 9 | UDP/8 | 04 | 9/29/2006 2:05:49 AM | 01.10 | |
| 10 | TCP/15660 | 03 | 9/29/2006 5:59:09 AM | 00.83 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP connection dropped | 275 | 9/29/2006 12:00:05 AM | 75.97 | |
| 2 | ICMP packet dropped | 56 | 9/29/2006 12:10:31 AM | 15.47 | |
| 3 | UDP packet dropped | 13 | 9/29/2006 1:27:14 AM | 03.59 | |
| 4 | Possible port scan dropped | 06 | 9/29/2006 5:58:11 AM | 01.66 | |
| 5 | Smurf Amplification attack dropped | 04 | 9/29/2006 2:05:49 AM | 01.10 | |
| 6 | Probable port scan dropped | 04 | 9/29/2006 5:58:21 AM | 01.10 | |
| 7 | Broadcast packet dropped | 02 | 9/29/2006 12:55:25 AM | 00.55 | |
| 8 | IPSec (ESP) packet dropped | 01 | 9/29/2006 1:40:21 AM | 00.28 | |
| 9 | Land attack dropped | 01 | 9/29/2006 6:58:53 AM | 00.28 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/443 - ssl-https | TCP connection dropped | 202 | 55.80 | |
| 2 | ICMP/3 - unreach | ICMP packet dropped | 42 | 11.60 | |
| 3 | TCP/25 - smtp | TCP connection dropped | 31 | 8.56 | |
| 4 | UDP/33438 | UDP packet dropped | 05 | 1.38 | |
| 5 | ICMP/13 | ICMP packet dropped | 05 | 1.38 | |
| 6 | TCP/15221 | TCP connection dropped | 05 | 1.38 | |
| 7 | ICMP/1 | ICMP packet dropped | 04 | 1.10 | |
| 8 | ICMP/0 | ICMP packet dropped | 04 | 1.10 | |
| 9 | UDP/8 | Smurf Amplification attack dropped | 04 | 1.10 | |
| 10 | TCP/15660 | TCP connection dropped | 03 | 0.83 |
Firewall: 72.13.230.2 - Interfaces: X2 to X0 - Go to top
Top 10 sources

Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols
Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | 342,666 | 67.36 | |
| 2 | mrc45-1-82-229-110-113.fbx.proxad.net (82.229.110.113) | 22,713 | 4.46 | |
| 3 | 220.125.142.15 | 15,819 | 3.11 | |
| 4 | modemcable186.22-202-24.mc.videotron.ca (24.202.22.186) | 13,649 | 2.68 | |
| 5 | 67.151.253.77 | 10,281 | 2.02 | 1 denials recorded on 9/29/2006 12:40:33 AM |
| 6 | adsl-68-19-89-93.flo.bellsouth.net (68.19.89.93) | 9,558 | 1.88 | |
| 7 | 211.49.2.238 | 5,873 | 1.15 | |
| 8 | 218.5.72.92 | 5,738 | 1.13 | |
| 9 | 67.151.253.80 | 5,419 | 1.07 | |
| 10 | 62.233.193.43 | 5,370 | 1.06 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 10.1.2.3 | 508,739 | 100.00 | 170 denials recorded on 9/29/2006 12:10:36 AM |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | TCP/4000 | 02 | 272,082 | 53.48 | |
| 2 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | TCP/4003 | 21 | 38,396 | 7.55 | |
| 3 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | TCP/135 - ms rpc | 30 | 29,352 | 5.77 | |
| 4 | mrc45-1-82-229-110-113.fbx.proxad.net (82.229.110.113) | SMTP | 01 | 22,713 | 4.46 | |
| 5 | 220.125.142.15 | SMTP | 01 | 15,819 | 3.11 | |
| 6 | modemcable186.22-202-24.mc.videotron.ca (24.202.22.186) | SMTP | 01 | 13,649 | 2.68 | |
| 7 | 67.151.253.77 | SMTP | 02 | 10,281 | 2.02 | 1 denials recorded on 9/29/2006 12:40:33 AM |
| 8 | adsl-68-19-89-93.flo.bellsouth.net (68.19.89.93) | SMTP | 01 | 9,558 | 1.88 | |
| 9 | 211.49.2.238 | SMTP | 01 | 5,873 | 1.15 | |
| 10 | 218.5.72.92 | SMTP | 01 | 5,738 | 1.13 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | 10.1.2.3 | TCP/4000 | 02 | 272,082 | 53.48 | 170 denials recorded on 9/29/2006 12:10:36 AM |
| 2 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | 10.1.2.3 | TCP/4003 | 21 | 38,396 | 7.55 | |
| 3 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | 10.1.2.3 | TCP/135 - ms rpc | 30 | 29,352 | 5.77 | |
| 4 | mrc45-1-82-229-110-113.fbx.proxad.net (82.229.110.113) | 10.1.2.3 | SMTP | 01 | 22,713 | 4.46 | |
| 5 | 220.125.142.15 | 10.1.2.3 | SMTP | 01 | 15,819 | 3.11 | |
| 6 | modemcable186.22-202-24.mc.videotron.ca (24.202.22.186) | 10.1.2.3 | SMTP | 01 | 13,649 | 2.68 | |
| 7 | 67.151.253.77 | 10.1.2.3 | SMTP | 02 | 10,281 | 2.02 | 1 denials recorded on 9/29/2006 12:40:33 AM |
| 8 | adsl-68-19-89-93.flo.bellsouth.net (68.19.89.93) | 10.1.2.3 | SMTP | 01 | 9,558 | 1.88 | |
| 9 | 211.49.2.238 | 10.1.2.3 | SMTP | 01 | 5,873 | 1.15 | |
| 10 | 218.5.72.92 | 10.1.2.3 | SMTP | 01 | 5,738 | 1.13 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/4000 | 02 | 272,082 | 53.48 | |
| 2 | SMTP | 38 | 166,073 | 32.64 | |
| 3 | TCP/4003 | 21 | 38,396 | 7.55 | |
| 4 | TCP/135 - ms rpc | 30 | 29,352 | 5.77 | |
| 5 | TCP/4001 | 02 | 2,836 | 0.56 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 67.151.253.6 | 02 | 9/29/2006 1:05:42 AM | 33.33 | 2 denials recorded on 9/29/2006 1:05:42 AM |
| 2 | 67.151.253.77 | 01 | 9/29/2006 12:40:33 AM | 16.67 | 1 denials recorded on 9/29/2006 12:40:33 AM |
| 3 | 200.31.26.28 | 01 | 9/29/2006 7:03:25 AM | 16.67 | 1 denials recorded on 9/29/2006 7:03:25 AM |
| 4 | 221.145.172.240 | 01 | 9/29/2006 10:12:36 AM | 16.67 | |
| 5 | chello062178221016.12.15.vie.surfer.at (62.178.221.16) | 01 | 9/29/2006 10:29:06 AM | 16.67 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 10.1.2.3 | 06 | 9/29/2006 12:40:33 AM | 100.00 | 170 denials recorded on 9/29/2006 12:10:36 AM |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/25 - smtp | 06 | 9/29/2006 12:40:33 AM | 100.00 |
Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP connection dropped | 06 | 9/29/2006 12:40:33 AM | 100.00 | 170 denials recorded on 9/29/2006 12:10:36 AM |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 67.151.253.6 | 10.1.2.3 | TCP/25 - smtp | TCP connection dropped | 02 | 9/29/2006 1:05:42 AM | 33.33 | 170 denials recorded on 9/29/2006 12:10:36 AM 170 denials recorded on 9/29/2006 12:10:36 AM 2 denials recorded on 9/29/2006 1:05:42 AM |
| 2 | 67.151.253.77 | 10.1.2.3 | TCP/25 - smtp | TCP connection dropped | 01 | 9/29/2006 12:40:33 AM | 16.67 | 1 denials recorded on 9/29/2006 12:40:33 AM |
| 3 | 200.31.26.28 | 10.1.2.3 | TCP/25 - smtp | TCP connection dropped | 01 | 9/29/2006 7:03:25 AM | 16.67 | 1 denials recorded on 9/29/2006 7:03:25 AM |
| 4 | 221.145.172.240 | 10.1.2.3 | TCP/25 - smtp | TCP connection dropped | 01 | 9/29/2006 10:12:36 AM | 16.67 | |
| 5 | chello062178221016.12.15.vie.surfer.at (62.178.221.16) | 10.1.2.3 | TCP/25 - smtp | TCP connection dropped | 01 | 9/29/2006 10:29:06 AM | 16.67 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/25 - smtp | TCP connection dropped | 06 | 100.00 |
Firewall: 72.13.230.2 - Interface: X2 - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | 4,845 | 43.24 | |
| 2 | ip-64-32-177-99.dsl.nyc.megapath.net (64.32.177.99) | 2,916 | 26.02 | |
| 3 | ool-44c17f09.dyn.optonline.net (68.193.127.9) | 2,028 | 18.10 | |
| 4 | mail.stempsystems.com (24.136.103.26) | 1,416 | 12.64 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | mail.stempsystems.com (24.136.103.26) | 9,789 | 87.36 | |
| 2 | ip-64-32-177-99.dsl.nyc.megapath.net (64.32.177.99) | 1,416 | 12.64 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | UDP/500 - ipsec | 08 | 4,845 | 43.24 | |
| 2 | ip-64-32-177-99.dsl.nyc.megapath.net (64.32.177.99) | UDP/500 - ipsec | 01 | 2,916 | 26.02 | |
| 3 | ool-44c17f09.dyn.optonline.net (68.193.127.9) | UDP/500 - ipsec | 01 | 2,028 | 18.10 | |
| 4 | mail.stempsystems.com (24.136.103.26) | UDP/500 - ipsec | 02 | 1,416 | 12.64 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | cpe-24-193-139-129.nyc.res.rr.com (24.193.139.129) | mail.stempsystems.com (24.136.103.26) | UDP/500 - ipsec | 08 | 4,845 | 43.24 | |
| 2 | ip-64-32-177-99.dsl.nyc.megapath.net (64.32.177.99) | mail.stempsystems.com (24.136.103.26) | UDP/500 - ipsec | 01 | 2,916 | 26.02 | |
| 3 | ool-44c17f09.dyn.optonline.net (68.193.127.9) | mail.stempsystems.com (24.136.103.26) | UDP/500 - ipsec | 01 | 2,028 | 18.10 | |
| 4 | mail.stempsystems.com (24.136.103.26) | ip-64-32-177-99.dsl.nyc.megapath.net (64.32.177.99) | UDP/500 - ipsec | 02 | 1,416 | 12.64 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/500 - ipsec | 12 | 11,205 | 100.00 |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | user-0c8hbfd.cable.mindspring.com (24.136.173.237) | 12 | 9/29/2006 1:54:59 AM | 22.22 | 12 denials recorded on 9/29/2006 1:54:59 AM |
| 2 | user-0c8hg8k.cable.mindspring.com (24.136.193.20) | 09 | 9/29/2006 12:22:33 AM | 16.67 | 9 denials recorded on 9/29/2006 12:22:33 AM |
| 3 | rrcs-24-136-118-145.nyc.biz.rr.com (24.136.118.145) | 08 | 9/29/2006 6:21:04 AM | 14.81 | 8 denials recorded on 9/29/2006 6:21:04 AM |
| 4 | rrcs-24-136-122-130.nyc.biz.rr.com (24.136.122.130) | 02 | 9/29/2006 2:11:12 AM | 03.70 | |
| 5 | user-0c8hb58.cable.mindspring.com (24.136.172.168) | 01 | 9/29/2006 12:15:14 AM | 01.85 | |
| 6 | 24-176-137-179.dhcp.plbg.ny.charter.com (24.176.137.179) | 01 | 9/29/2006 12:17:45 AM | 01.85 | |
| 7 | rrcs-24-136-96-177.nyc.biz.rr.com (24.136.96.177) | 01 | 9/29/2006 12:47:08 AM | 01.85 | |
| 8 | S0106001346ac3007.vs.shawcable.net (24.83.89.155) | 01 | 9/29/2006 12:58:14 AM | 01.85 | |
| 9 | 24.85.215.114 | 01 | 9/29/2006 1:34:40 AM | 01.85 | |
| 10 | 24.85.144.184 | 01 | 9/29/2006 2:26:40 AM | 01.85 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | mail.stempsystems.com (24.136.103.26) | 54 | 9/29/2006 12:15:14 AM | 100.00 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/445 - netbios | 40 | 9/29/2006 12:15:14 AM | 74.07 | |
| 2 | TCP/135 - ms rpc | 03 | 9/29/2006 2:26:40 AM | 05.56 | |
| 3 | TCP/4899 - radmin | 02 | 9/29/2006 3:19:15 AM | 03.70 | |
| 4 | ICMP/0 | 02 | 9/29/2006 3:40:38 AM | 03.70 | |
| 5 | TCP/139 - netbios | 01 | 9/29/2006 1:34:40 AM | 01.85 | |
| 6 | UDP/1029 | 01 | 9/29/2006 3:51:34 AM | 01.85 | |
| 7 | TCP/1433 - ms sql | 01 | 9/29/2006 4:27:28 AM | 01.85 | |
| 8 | UDP/137 - netbios | 01 | 9/29/2006 4:52:24 AM | 01.85 | |
| 9 | TCP/9898 | 01 | 9/29/2006 5:10:39 AM | 01.85 | |
| 10 | TCP/25 - smtp | 01 | 9/29/2006 6:28:38 AM | 01.85 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP connection dropped | 50 | 9/29/2006 12:15:14 AM | 92.59 | |
| 2 | ICMP packet dropped | 02 | 9/29/2006 3:40:38 AM | 03.70 | |
| 3 | UDP packet dropped | 02 | 9/29/2006 3:51:34 AM | 03.70 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/445 - netbios | TCP connection dropped | 40 | 74.07 | |
| 2 | TCP/135 - ms rpc | TCP connection dropped | 03 | 5.56 | |
| 3 | TCP/4899 - radmin | TCP connection dropped | 02 | 3.70 | |
| 4 | ICMP/0 | ICMP packet dropped | 02 | 3.70 | |
| 5 | TCP/139 - netbios | TCP connection dropped | 01 | 1.85 | |
| 6 | UDP/1029 | UDP packet dropped | 01 | 1.85 | |
| 7 | TCP/1433 - ms sql | TCP connection dropped | 01 | 1.85 | |
| 8 | UDP/137 - netbios | UDP packet dropped | 01 | 1.85 | |
| 9 | TCP/9898 | TCP connection dropped | 01 | 1.85 | |
| 10 | TCP/25 - smtp | TCP connection dropped | 01 | 1.85 |
Firewall: 72.13.230.2 - Interfaces: X1 to - Go to top
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols
Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | user-0ccevrl.cable.mindspring.com (24.199.127.117) | 03 | 9/29/2006 12:32:16 AM | 100.00 | 3 denials recorded on 9/29/2006 12:32:16 AM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | 03 | 9/29/2006 12:32:16 AM | 100.00 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/500 - ipsec | 03 | 9/29/2006 12:32:16 AM | 100.00 |
Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP packet dropped | 03 | 9/29/2006 12:32:16 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | user-0ccevrl.cable.mindspring.com (24.199.127.117) | 2-230-13-72.static.cosmoweb.net (72.13.230.2) | UDP/500 - ipsec | UDP packet dropped | 03 | 9/29/2006 12:32:16 AM | 100.00 | 3 denials recorded on 9/29/2006 12:32:16 AM |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/500 - ipsec | UDP packet dropped | 03 | 100.00 |
Firewall: 72.13.230.2 - Interfaces: Not specified - Go to top
Top 10 warning messages
| No | Code | Message sample | Count | Comment |
|---|---|---|---|---|
| 1 | 640 | msg="Received ISAKMP packet destined to port 500, expected on floated port 4500" n=944 src=68.39.142.55:500::pcp04208994pcs.brick101.nj.comcast.net dst=72.13.230.2:500::2-230-13-72.cosmoweb.net | 527 | |
| 2 | 512 | msg="ARP timeout" n=5208 src=0.0.0.0 dst=10.1.2.119 | 112 | |
| 3 | 1048576 | msg="VoIP 10.1.2.1 (H.323) Endpoint removed" n=4 | 6 | |
| To assist us in improving the analyzer, please send the messages above to support@firegen.com and they will be added to the next release of Firegen. | ||||
Analysis details
| Analysis start time | 11/15/2011 7:08:08 PM |
| Analysis duration | 2.96 minutes (177 seconds) |
| Analysis engine version | Sonicwall parser version: 0.02 FireGen30Service.exe - FireGen scheduler service: 3.0.0.0 |
| Filtering criteria | All entries |
| Excluded keywords | None |
Glossary
| !!! | Indicates that a high denials:connections ration has been detected. The current configured ratio is 3. The !!! indicates that the percentage of denials for that hour is bigger than 3 x the connections percentage. This indicates some unusual denial activity that may have to be investigated. The ratio can be configured on the Report Formats interface. |
| Other messages | The Other messages represents a list of message not yet configured in the Firegen parser. Please send these messages to us (support@firegen.com) and we will add them in the next Firegen update. These messages are included in the list of message types but they are not yet fully understood by the analyzer. |