FireGen Report
| Info | Value |
|---|---|
| Log profile | Log profile Cisco IOS |
| Analyzed log(s) |
F:\Logs\AdTran\Syslog-2008-01-07.log (10.00 MB) |
| Firewall type | AdTran |
| Analysis interval | All entries in the specified log |
Firewalls
| No | Firewall | Connections | Traffic (MB) | Denials | Warnings | URLs | 1 | FIREWALL_TO | 407 | 04.22 | 37 | 00 | 00 |
|---|
Message types
| No | Code | Message sample | Count | 2 | 1 | rule=22 proto=telnet src=192.168.1.93 dst=192.168.1.50 msg="Zero bytes transferred for connection Src 3846 Dst 23 from private policy-class" agent=AdFirewall | 41 | 3 | 6 | rule=23 proto=256/icmp src=192.168.1.93 dst=192.168.5.15 msg="Connection timed out.Bytes transferred : 12 from private policy-class" agent=AdFirewall | 876 |
|---|
Firewall: FIREWALL_TO
FIREWALL_TO - Traffic and denials per hour




| Hour | Traffic (MB) | % | Connections | % | Denials | % | |
|---|---|---|---|---|---|---|---|
| 00-01 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 01-02 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 02-03 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 03-04 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 04-05 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 05-06 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 06-07 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 07-08 | 00.00 | 0.00 | 03 | 0.68 | 03 | 8.11 | !!! |
| 08-09 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 09-10 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 10-11 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 11-12 | 00.00 | 15.49 | 28 | 6.31 | 05 | 13.51 | |
| 12-13 | 00.00 | 10.82 | 86 | 19.37 | 03 | 8.11 | |
| 13-14 | 00.00 | 15.63 | 60 | 13.51 | 03 | 8.11 | |
| 14-15 | 00.00 | 10.56 | 38 | 8.56 | 02 | 5.41 | |
| 15-16 | 00.00 | 10.80 | 38 | 8.56 | 00 | 0.00 | |
| 16-17 | 00.00 | 1.23 | 39 | 8.78 | 02 | 5.41 | |
| 17-18 | 00.00 | 9.22 | 36 | 8.11 | 01 | 2.70 | |
| 18-19 | 00.00 | 15.58 | 44 | 9.91 | 05 | 13.51 | |
| 19-20 | 00.00 | 3.78 | 36 | 8.11 | 01 | 2.70 | |
| 20-21 | 00.00 | 6.89 | 25 | 5.63 | 01 | 2.70 | |
| 21-22 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
| 22-23 | 00.00 | 0.00 | 00 | 0.00 | 00 | 0.00 | |
| 23-24 | 00.00 | 0.00 | 01 | 0.23 | 01 | 2.70 | !!! |
FIREWALL_TO - Interfaces
| No | Interfaces | Connections | MB | % | Denials | Warnings |
|---|---|---|---|---|---|---|
| 1 | ppp to If | 18 | 00.02 | 00.42 | 14 | 00 |
| 2 | private to If | 388 | 04.20 | 99.56 | 18 | 00 |
| 3 | SELF to If | 01 | 00.00 | 00.02 | 03 | 00 |
| 4 | comcast to If | 00 | 00.00 | 00.00 | 02 | 00 |
| Total | 407 | 04.22 | 37 | 00 |
Firewall: FIREWALL_TO - Interfaces: ppp to If - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.100.58 | 9,271 | 50.08 | |
| 2 | 192.168.100.61 | 3,484 | 18.82 | |
| 3 | 190.49.45.154 | 1,133 | 6.12 | |
| 4 | 65-125-49-210.dia.static.qwest.net (65.125.49.210) | 1,076 | 5.81 | |
| 5 | 201.216.9.254 | 775 | 4.19 | |
| 6 | pool-71-168-108-241.cncdnh.fast02.myfairpoint.net (71.168.108.241) | 577 | 3.12 | |
| 7 | 202.57.163.192 | 560 | 3.03 | |
| 8 | 200.31.173.29 | 532 | 2.87 | |
| 9 | 200.188.209.84.dedicated.neoviatelecom.com.br (200.188.209.84) | 510 | 2.75 | |
| 10 | adsl-84-227-86-131.adslplus.ch (84.227.86.131) | 322 | 1.74 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.110 | 8,392 | 45.33 | 3 denials recorded on 1/7/2008 9:56:48 AM |
| 2 | 192.168.1.87 | 4,555 | 24.61 | |
| 3 | mail.bucksfirstfcu.com (65.115.231.163) | 4,409 | 23.82 | 360 denials recorded on 10/28/2011 3:37:55 AM |
| 4 | 65.119.198.166 | 1,076 | 5.81 | 3 denials recorded on 1/7/2008 2:43:17 AM |
| 5 | 192.168.1.93 | 80 | 0.43 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.100.58 | TCP/4479 | 01 | 8,008 | 43.26 | |
| 2 | 192.168.100.61 | TCP/1025 - agobot-worm | 02 | 2,640 | 14.26 | |
| 3 | 190.49.45.154 | SMTP | 01 | 1,133 | 6.12 | |
| 4 | 65-125-49-210.dia.static.qwest.net (65.125.49.210) | UDP/500 - ipsec | 01 | 1,076 | 5.81 | |
| 5 | 192.168.100.58 | UDP/53 - dns | 02 | 1,071 | 5.79 | |
| 6 | 201.216.9.254 | SMTP | 01 | 775 | 4.19 | |
| 7 | pool-71-168-108-241.cncdnh.fast02.myfairpoint.net (71.168.108.241) | SMTP | 01 | 577 | 3.12 | |
| 8 | 202.57.163.192 | SMTP | 01 | 560 | 3.03 | |
| 9 | 200.31.173.29 | SMTP | 01 | 532 | 2.87 | |
| 10 | 200.188.209.84.dedicated.neoviatelecom.com.br (200.188.209.84) | SMTP | 01 | 510 | 2.75 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.100.58 | 192.168.1.110 | TCP/4479 | 01 | 8,008 | 43.26 | 3 denials recorded on 1/7/2008 9:56:48 AM |
| 2 | 192.168.100.61 | 192.168.1.87 | TCP/1025 - agobot-worm | 02 | 2,640 | 14.26 | |
| 3 | 190.49.45.154 | mail.bucksfirstfcu.com (65.115.231.163) | SMTP | 01 | 1,133 | 6.12 | 360 denials recorded on 10/28/2011 3:37:55 AM |
| 4 | 65-125-49-210.dia.static.qwest.net (65.125.49.210) | 65.119.198.166 | UDP/500 - ipsec | 01 | 1,076 | 5.81 | 3 denials recorded on 1/7/2008 2:43:17 AM |
| 5 | 192.168.100.58 | 192.168.1.87 | UDP/53 - dns | 02 | 1,071 | 5.79 | |
| 6 | 201.216.9.254 | mail.bucksfirstfcu.com (65.115.231.163) | SMTP | 01 | 775 | 4.19 | |
| 7 | pool-71-168-108-241.cncdnh.fast02.myfairpoint.net (71.168.108.241) | mail.bucksfirstfcu.com (65.115.231.163) | SMTP | 01 | 577 | 3.12 | |
| 8 | 202.57.163.192 | mail.bucksfirstfcu.com (65.115.231.163) | SMTP | 01 | 560 | 3.03 | |
| 9 | 200.31.173.29 | mail.bucksfirstfcu.com (65.115.231.163) | SMTP | 01 | 532 | 2.87 | |
| 10 | 200.188.209.84.dedicated.neoviatelecom.com.br (200.188.209.84) | mail.bucksfirstfcu.com (65.115.231.163) | SMTP | 01 | 510 | 2.75 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP/4479 | 01 | 8,008 | 43.26 | |
| 2 | SMTP | 07 | 4,409 | 23.82 | |
| 3 | TCP/1025 - agobot-worm | 02 | 2,640 | 14.26 | |
| 4 | UDP/500 - ipsec | 01 | 1,076 | 5.81 | |
| 5 | UDP/53 - dns | 02 | 1,071 | 5.79 | |
| 6 | TCP/135 - ms rpc | 03 | 824 | 4.45 | |
| 7 | LDAP | 01 | 404 | 2.18 | |
| 8 | TCP/5177 | 01 | 80 | 0.43 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 80-239-229-195.customer.teliacarrier.com (80.239.229.195) | 02 | 1/7/2008 6:14:49 PM | 14.29 | 2 denials recorded on 1/7/2008 6:14:49 PM |
| 2 | testmq.myinterlend.com (151.196.64.41) | 01 | 1/6/2008 9:59:48 PM | 07.14 | 1 denials recorded on 1/6/2008 9:59:48 PM |
| 3 | host81-148-90-144.in-addr.btopenworld.com (81.148.90.144) | 01 | 1/7/2008 12:00:45 AM | 07.14 | 1 denials recorded on 1/7/2008 12:00:45 AM |
| 4 | smtp0.ctinetworks.com (205.166.61.207) | 01 | 1/7/2008 8:39:39 AM | 07.14 | |
| 5 | 207.138.125.248 | 01 | 1/7/2008 11:48:28 AM | 07.14 | |
| 6 | 216.218.219.41 | 01 | 1/7/2008 11:48:32 AM | 07.14 | |
| 7 | mail.homecu.net (199.184.207.89) | 01 | 1/7/2008 12:46:32 PM | 07.14 | 360 denials recorded on 10/28/2011 3:37:55 AM |
| 8 | w197.z065107215.bos-ma.dsl.cnc.net (65.107.215.197) | 01 | 1/7/2008 1:13:50 PM | 07.14 | |
| 9 | 209.170.118.42 | 01 | 1/7/2008 1:17:30 PM | 07.14 | |
| 10 | 65.113.110.149 | 01 | 1/7/2008 2:27:01 PM | 07.14 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 65.119.198.166 | 08 | 1/6/2008 9:59:48 PM | 57.14 | 3 denials recorded on 1/7/2008 2:43:17 AM |
| 2 | mail.bucksfirstfcu.com (65.115.231.163) | 05 | 1/7/2008 12:00:45 AM | 35.71 | 360 denials recorded on 10/28/2011 3:37:55 AM |
| 3 | 65-115-231-162.dia.static.qwest.net (65.115.231.162) | 01 | 1/7/2008 1:13:50 PM | 07.14 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP/8 - ping | 05 | 1/7/2008 11:48:28 AM | 35.71 | |
| 2 | SMTP | 03 | 1/7/2008 12:00:45 AM | 21.43 | |
| 3 | TCP/4751 | 01 | 1/6/2008 9:59:48 PM | 07.14 | |
| 4 | TCP/135 - ms rpc | 01 | 1/7/2008 1:13:50 PM | 07.14 | |
| 5 | TCP/2565 | 01 | 1/7/2008 1:17:30 PM | 07.14 | |
| 6 | TCP/1433 - ms sql | 01 | 1/7/2008 2:27:01 PM | 07.14 | |
| 7 | UDP/1026 - blaster-worm | 01 | 1/7/2008 4:23:44 PM | 07.14 | |
| 8 | UDP/54305 | 01 | 1/7/2008 6:14:25 PM | 07.14 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | No Access Policy matched | 09 | 1/7/2008 11:48:28 AM | 64.29 | |
| 2 | TCP connection request received is invalid (expected SYN, got ACK) | 02 | 1/6/2008 9:59:48 PM | 14.29 | |
| 3 | Invalid sequence number received with RST | 02 | 1/7/2008 8:39:39 AM | 14.29 | |
| 4 | TCP connection request received is invalid (expecting SYN only) | 01 | 1/7/2008 1:17:30 PM | 07.14 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP/8 - ping | No Access Policy matched | 05 | 35.71 | |
| 2 | SMTP | Invalid sequence number received with RST | 02 | 14.29 | |
| 3 | TCP/4751 | TCP connection request received is invalid (expected SYN, got ACK) | 01 | 7.14 | |
| 4 | SMTP | TCP connection request received is invalid (expected SYN, got ACK) | 01 | 7.14 | |
| 5 | TCP/135 - ms rpc | No Access Policy matched | 01 | 7.14 | |
| 6 | TCP/2565 | TCP connection request received is invalid (expecting SYN only) | 01 | 7.14 | |
| 7 | TCP/1433 - ms sql | No Access Policy matched | 01 | 7.14 | |
| 8 | UDP/1026 - blaster-worm | No Access Policy matched | 01 | 7.14 | |
| 9 | UDP/54305 | No Access Policy matched | 01 | 7.14 |
Firewall: FIREWALL_TO - Interfaces: private to If - Go to top
Top 10 sources

Top 10 destinations

Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols

Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 192.168.1.101 | 1,402,532 | 31.82 | |
| 2 | 192.168.1.99 | 1,001,402 | 22.72 | |
| 3 | 192.168.1.96 | 447,702 | 10.16 | 11 denials recorded on 1/6/2008 11:11:33 PM |
| 4 | 192.168.1.238 | 408,461 | 9.27 | |
| 5 | 192.168.1.47 | 284,944 | 6.46 | |
| 6 | 192.168.1.81 | 248,827 | 5.64 | |
| 7 | 192.168.1.9 | 173,544 | 3.94 | |
| 8 | 192.168.1.11 | 162,144 | 3.68 | 3 denials recorded on 1/7/2008 9:56:48 AM |
| 9 | 192.168.1.93 | 128,817 | 2.92 | |
| 10 | 192.168.1.8 | 62,230 | 1.41 |

Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | testmq.myinterlend.com (151.196.64.41) | 1,402,532 | 31.82 | 1 denials recorded on 1/6/2008 9:59:48 PM |
| 2 | mq.myinterlend.com (151.196.64.38) | 1,001,402 | 22.72 | |
| 3 | 216.129.105.112 | 440,216 | 9.99 | |
| 4 | 216.178.38.143 | 298,357 | 6.77 | |
| 5 | 209.170.118.42 | 165,419 | 3.75 | |
| 6 | 204.17.42.250 | 164,379 | 3.73 | |
| 7 | 209.10.160.46 | 142,155 | 3.22 | |
| 8 | 209.170.118.58 | 135,062 | 3.06 | |
| 9 | 4a.25.364a.static.theplanet.com (74.54.37.74) | 99,545 | 2.26 | |
| 10 | relay.verizon.net (206.46.232.11) | 98,528 | 2.24 |

Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 192.168.1.101 | HTTPS | 22 | 1,402,532 | 31.82 | |
| 2 | 192.168.1.99 | HTTPS | 10 | 1,001,402 | 22.72 | |
| 3 | 192.168.1.96 | HTTP | 03 | 442,059 | 10.03 | 11 denials recorded on 1/6/2008 11:11:33 PM |
| 4 | 192.168.1.238 | HTTP | 05 | 408,461 | 9.27 | |
| 5 | 192.168.1.47 | HTTP | 05 | 284,944 | 6.46 | |
| 6 | 192.168.1.81 | HTTP | 09 | 248,827 | 5.64 | |
| 7 | 192.168.1.9 | HTTP | 03 | 173,544 | 3.94 | |
| 8 | 192.168.1.11 | HTTP | 20 | 125,497 | 2.85 | 3 denials recorded on 1/7/2008 9:56:48 AM |
| 9 | 192.168.1.93 | SMTP | 01 | 98,528 | 2.24 | |
| 10 | 192.168.1.8 | HTTP | 04 | 62,230 | 1.41 |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 192.168.1.101 | testmq.myinterlend.com (151.196.64.41) | HTTPS | 22 | 1,402,532 | 31.82 | 1 denials recorded on 1/6/2008 9:59:48 PM |
| 2 | 192.168.1.99 | mq.myinterlend.com (151.196.64.38) | HTTPS | 10 | 1,001,402 | 22.72 | |
| 3 | 192.168.1.96 | 216.129.105.112 | HTTP | 01 | 440,216 | 9.99 | 11 denials recorded on 1/6/2008 11:11:33 PM |
| 4 | 192.168.1.238 | 216.178.38.143 | HTTP | 01 | 298,357 | 6.77 | |
| 5 | 192.168.1.9 | 209.170.118.42 | HTTP | 01 | 165,419 | 3.75 | |
| 6 | 192.168.1.81 | 204.17.42.250 | HTTP | 04 | 164,379 | 3.73 | |
| 7 | 192.168.1.47 | 209.10.160.46 | HTTP | 01 | 142,155 | 3.22 | |
| 8 | 192.168.1.47 | 209.170.118.58 | HTTP | 01 | 135,062 | 3.06 | |
| 9 | 192.168.1.238 | 4a.25.364a.static.theplanet.com (74.54.37.74) | HTTP | 01 | 99,545 | 2.26 | |
| 10 | 192.168.1.93 | relay.verizon.net (206.46.232.11) | SMTP | 01 | 98,528 | 2.24 |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTPS | 39 | 2,474,874 | 56.14 | |
| 2 | HTTP | 55 | 1,784,133 | 40.47 | |
| 3 | SMTP | 03 | 99,177 | 2.25 | |
| 4 | TCP/1025 - agobot-worm | 05 | 20,584 | 0.47 | |
| 5 | UDP/53 - dns | 20 | 8,428 | 0.19 | |
| 6 | ICMP | 02 | 5,888 | 0.13 | |
| 7 | TCP/50668 | 03 | 5,448 | 0.12 | |
| 8 | ICMP/256 | 242 | 3,707 | 0.08 | |
| 9 | UDP/137 - netbios | 11 | 2,746 | 0.06 | |
| 10 | TCP/135 - ms rpc | 03 | 2,696 | 0.06 |

Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 192.168.1.96 | 11 | 1/6/2008 11:11:33 PM | 61.11 | 11 denials recorded on 1/6/2008 11:11:33 PM |
| 2 | 192.168.1.11 | 03 | 1/7/2008 9:56:48 AM | 16.67 | 3 denials recorded on 1/7/2008 9:56:48 AM |
| 3 | 192.168.1.17 | 02 | 1/7/2008 5:25:20 AM | 11.11 | 2 denials recorded on 1/7/2008 5:25:20 AM |
| 4 | 192.168.1.81 | 01 | 1/7/2008 7:50:56 AM | 05.56 | |
| 5 | 192.168.1.238 | 01 | 1/7/2008 11:49:43 AM | 05.56 |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 216.129.105.129 | 02 | 1/7/2008 3:35:17 AM | 11.11 | |
| 2 | www.midatlanticcorp.org (12.20.249.19) | 02 | 1/7/2008 5:25:20 AM | 11.11 | |
| 3 | 59.39.202.198 | 01 | 1/6/2008 11:11:33 PM | 05.56 | |
| 4 | mail.itsolutions.bg (77.70.13.150) | 01 | 1/7/2008 1:14:18 AM | 05.56 | 360 denials recorded on 10/28/2011 3:37:55 AM |
| 5 | 58.69.66.96 | 01 | 1/7/2008 4:59:30 AM | 05.56 | |
| 6 | eforwardct.name-services.com (216.163.188.58) | 01 | 1/7/2008 7:00:41 AM | 05.56 | |
| 7 | 204.17.42.208 | 01 | 1/7/2008 7:50:56 AM | 05.56 | |
| 8 | 65.127.196.71 | 01 | 1/7/2008 9:56:48 AM | 05.56 | |
| 9 | 89.149.84.235 | 01 | 1/7/2008 10:27:01 AM | 05.56 | |
| 10 | 205.203.131.55 | 01 | 1/7/2008 11:24:12 AM | 05.56 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | HTTP | 07 | 1/7/2008 3:35:17 AM | 38.89 | |
| 2 | HTTPS | 03 | 1/7/2008 5:25:20 AM | 16.67 | |
| 3 | SMTP | 02 | 1/7/2008 7:00:41 AM | 11.11 | |
| 4 | TCP/24729 | 01 | 1/6/2008 11:11:33 PM | 05.56 | |
| 5 | TCP/3935 | 01 | 1/7/2008 1:14:18 AM | 05.56 | |
| 6 | TCP/16784 | 01 | 1/7/2008 4:59:30 AM | 05.56 | |
| 7 | TCP/3958 | 01 | 1/7/2008 10:27:01 AM | 05.56 | |
| 8 | TCP/2819 | 01 | 1/7/2008 12:03:58 PM | 05.56 | |
| 9 | TCP/2774 | 01 | 1/7/2008 1:46:18 PM | 05.56 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | TCP connection request received is invalid (expected SYN, got ACK) | 17 | 1/6/2008 11:11:33 PM | 94.44 | |
| 2 | Invalid sequence number received with RST | 01 | 1/7/2008 11:24:12 AM | 05.56 |

Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
Firewall: FIREWALL_TO - Interfaces: SELF to If - Go to top
Top 10 sources
Top 10 destinations
Top 10 sources, protocols and bytes
Top 10 sources, destinations, protocols and bytes
Top 10 protocols
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols
Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 65.119.198.166 | 924 | 100.00 | 3 denials recorded on 1/7/2008 2:43:17 AM |
Top 10 destinations
| No | Destination | Bytes | % | Comment |
|---|---|---|---|---|
| 1 | 216.189.255.12 | 924 | 100.00 |
Top 10 sources, protocols and bytes
| No | Source | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|
| 1 | 65.119.198.166 | UDP/500 - ipsec | 01 | 924 | 100.00 | 3 denials recorded on 1/7/2008 2:43:17 AM |
Top 10 sources, destinations, protocols and bytes
| No | Source | Destination | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|---|---|
| 1 | 65.119.198.166 | 216.189.255.12 | UDP/500 - ipsec | 01 | 924 | 100.00 | 3 denials recorded on 1/7/2008 2:43:17 AM |
Top 10 protocols
| No | Protocol | Connections | Bytes | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/500 - ipsec | 01 | 924 | 100.00 |
Top 10 denied sources
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 65.119.198.166 | 03 | 1/7/2008 2:43:17 AM | 100.00 | 3 denials recorded on 1/7/2008 2:43:17 AM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | c-76-108-54-130.hsd1.fl.comcast.net (76.108.54.130) | 01 | 1/7/2008 2:43:17 AM | 33.33 | |
| 2 | chello062178002193.1.11.vie.surfer.at (62.178.2.193) | 01 | 1/7/2008 4:19:42 PM | 33.33 | |
| 3 | static-66-12-230-242.bdsl.verizon.net (66.12.230.242) | 01 | 1/7/2008 7:23:51 PM | 33.33 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP | 03 | 1/7/2008 2:43:17 AM | 100.00 |
Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP Type: 0 Code: 0 Echo response for uninitiated echo request(Possible Smurf Attack) | 03 | 1/7/2008 2:43:17 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 65.119.198.166 | c-76-108-54-130.hsd1.fl.comcast.net (76.108.54.130) | ICMP | ICMP Type: 0 Code: 0 Echo response for uninitiated echo request(Possible Smurf Attack) | 01 | 1/7/2008 2:43:17 AM | 33.33 | 3 denials recorded on 1/7/2008 2:43:17 AM |
| 2 | 65.119.198.166 | chello062178002193.1.11.vie.surfer.at (62.178.2.193) | ICMP | ICMP Type: 0 Code: 0 Echo response for uninitiated echo request(Possible Smurf Attack) | 01 | 1/7/2008 4:19:42 PM | 33.33 | |
| 3 | 65.119.198.166 | static-66-12-230-242.bdsl.verizon.net (66.12.230.242) | ICMP | ICMP Type: 0 Code: 0 Echo response for uninitiated echo request(Possible Smurf Attack) | 01 | 1/7/2008 7:23:51 PM | 33.33 |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | ICMP | ICMP Type: 0 Code: 0 Echo response for uninitiated echo request(Possible Smurf Attack) | 03 | 100.00 |
Firewall: FIREWALL_TO - Interfaces: comcast to If - Go to top
Top 10 denied sources
Top 10 destinations for denied connections
Top 10 denied protocols

Top 10 denial reasons
Top 10 denied sources, destinations, protocols and reasons
Top 10 denied protocols and reasons
| No | Source | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 222.161.2.24 | 01 | 1/7/2008 11:51:55 AM | 50.00 | 1 denials recorded on 1/7/2008 11:51:55 AM |
| 2 | 122-124-161-149.dynamic.hinet.net (122.124.161.149) | 01 | 1/7/2008 8:07:50 PM | 50.00 | 1 denials recorded on 1/7/2008 8:07:50 PM |
Top 10 destinations for denied connections
| No | Destination | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | 74-94-9-125-philadelphia-panjde.hfc.comcastbusiness.net (74.94.9.125) | 02 | 1/7/2008 11:51:55 AM | 100.00 |
Top 10 denied protocols
| No | Denied protocol | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/1027 - blaster-worm | 01 | 1/7/2008 11:51:55 AM | 50.00 | |
| 2 | SMTP | 01 | 1/7/2008 8:07:50 PM | 50.00 |

Top 10 denial reasons
| No | Denial reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|
| 1 | No Access Policy matched | 02 | 1/7/2008 11:51:55 AM | 100.00 |
Top 10 denied sources, destinations, protocols and reasons
| No | Source | Destination | Protocol | Reason | Connections | First denial | % | Comment |
|---|---|---|---|---|---|---|---|---|
| 1 | 222.161.2.24 | 74-94-9-125-philadelphia-panjde.hfc.comcastbusiness.net (74.94.9.125) | UDP/1027 - blaster-worm | No Access Policy matched | 01 | 1/7/2008 11:51:55 AM | 50.00 | 1 denials recorded on 1/7/2008 11:51:55 AM |
| 2 | 122-124-161-149.dynamic.hinet.net (122.124.161.149) | 74-94-9-125-philadelphia-panjde.hfc.comcastbusiness.net (74.94.9.125) | SMTP | No Access Policy matched | 01 | 1/7/2008 8:07:50 PM | 50.00 | 1 denials recorded on 1/7/2008 8:07:50 PM |
Top 10 denied protocols and reasons
| No | Protocol | Reason | Denials | % | Comment |
|---|---|---|---|---|---|
| 1 | UDP/1027 - blaster-worm | No Access Policy matched | 01 | 50.00 | |
| 2 | SMTP | No Access Policy matched | 01 | 50.00 |
| No | Code | Message sample | Count | Comment |
|---|---|---|---|---|
| 1 | 6 | proto=esp src=65.119.198.166 dst=65.125.49.210 vpn=9-2 type=1 msg="Outbound SA Life Time Expired - SPI 0x4bda0f12, Remote ID 65.125.49.210" agent=iSecure 1.0 | 36 | 3 denials recorded on 1/7/2008 2:43:17 AM |
| To assist us in improving the analyzer, please send the messages above to support@firegen.com and they will be added to the next release of Firegen. | ||||
Analysis details
| Analysis start time | 11/15/2011 7:54:04 PM |
| Analysis duration | 0.64 minutes (38 seconds) |
| Analysis engine version | AdTran parser version: 0.01 FireGen30Service.exe - FireGen scheduler service: 3.0.0.0 |
| Filtering criteria | All entries |
| Excluded keywords | None |
Glossary
| !!! | Indicates that a high denials:connections ration has been detected. The current configured ratio is 3. The !!! indicates that the percentage of denials for that hour is bigger than 3 x the connections percentage. This indicates some unusual denial activity that may have to be investigated. The ratio can be configured on the Report Formats interface. |
| Other messages | The Other messages represents a list of message not yet configured in the Firegen parser. Please send these messages to us (support@firegen.com) and we will add them in the next Firegen update. These messages are included in the list of message types but they are not yet fully understood by the analyzer. |