Logo
 
firegen home | support | tcp/ip ports | logwiki | support forums
Altair Technologies Ltd. - Firegen report generated on 11/15/2011 7:34:10 PM

FireGen Report
InfoValue
Log profileLog profile Cisco IOS
Analyzed log(s) F:\Logs\Cisco Router\syslog-rtr-2006-11-13.txt (12.00 MB)

Firewall typeCisco IOS
Analysis intervalAll entries in the specified log
Firewalls
NoFirewallConnectionsTraffic (MB)DenialsWarningsURLs
110.1.10.260,7271,291.65180100
Message types
NoCodeMessage sampleCount
2CRYPTO-3-QUERY_KEYQuerying key pair failed.2,779
3CRYPTO-4-IKMP_BAD_MESSAGEIKE message from 217.118.237.6 failed its sanity check or is malformed1,375
4CRYPTO-4-IKMP_PKT_OVERFLOWISAKMP message from 216.153.137.34 larger (-308757567) than the UDP packet length (92)01
5DUAL-5-NBRCHANGEIP-EIGRP(0) 10: Neighbor 10.255.1.202 (Tunnel106) is up: new adjacency02
6FW-2-BLOCK_HOSTBlocking new TCP connections to host 66.193.23.113 for 2 minutes (half-open count 50 exceeded).01
7FW-3-HTTP_JAVA_BLOCKJAVA applet is blocked from (209.157.71.50:80) to (10.1.100.142:4416).16
8FW-3-RESPONDER_WND_SCALE_INI_NO_SCALEDropping packet - Invalid Window Scale option for session 10.1.100.149:3314 to 70.96.241.242:80 (Initiator scale 0 Responder scale 0)01
9FW-4-HOST_TCP_ALERT_ONMax tcp half-open connections (50) exceeded for host 66.193.23.113.01
10FW-4-UNBLOCK_HOSTNew TCP connections to host 66.193.23.113 no longer blocked01
11FW-6-SESS_AUDIT_TRAILudp session initiator (10.1.1.59:1349) sent 126 bytes -- responder (204.117.214.10:53) sent 797 bytes60,727
12VPN_HW-4-PACKET_ERRORslot: 0 Packet Encryption/Decryption error, Output Authentication error:srcadr=211.75.163.90,dstadr=144.232.212.18,size=168,handle=0x59D504
Firewall: 10.1.10.2

10.1.10.2 - Traffic and denials per hour









HourTraffic (MB)%Connections%Denials%
00-0100.000.046991.15000.00
01-0206.000.504560.75000.00
02-0308.000.635960.98000.00
03-0419.001.497491.23000.00
04-0507.000.598801.45000.00
05-0601.000.145810.96000.00
06-0702.000.185490.90000.00
07-0804.000.326551.08000.00
08-0994.007.305,5279.10000.00
09-10105.008.165,4498.97000.00
10-11181.0014.076,48910.680844.44!!!
11-12128.009.956,07210.00015.56
12-13190.0014.724,0326.64000.00
13-1498.007.614,9878.21000.00
14-15103.008.004,5447.48000.00
15-1682.006.424,3897.230844.44!!!
16-1791.007.104,4747.37015.56
17-18108.008.434,5217.44000.00
18-1929.002.281,7202.83000.00
19-2011.000.899481.56000.00
20-2103.000.295340.88000.00
21-2204.000.328031.32000.00
22-2303.000.305090.84000.00
23-2403.000.295820.96000.00
10.1.10.2 - Interfaces
NoInterfacesConnectionsMB%DenialsWarnings
1Not specified60,7271,291.65100.001801
 Total60,7271,291.65 1801
Firewall: 10.1.10.2 - Interfaces: Not specified - Go to top
Top 10 sources
NoSourceBytes%Comment
110.1.1.19288,917,78921.33 
210.1.100.138152,284,84511.24 
310.1.100.15982,145,8406.07 
410.1.100.14355,841,1064.12 
510.1.100.14452,618,0123.88 
610.1.100.11851,867,5443.83 
710.1.100.14951,274,9973.791 denials recorded on 11/13/2006 4:32:48 PM
810.1.100.10347,923,7693.54 
910.1.90.10144,240,5483.27 
1010.1.100.14239,627,7452.93 



Top 10 destinations
NoDestinationBytes%Comment
1outbounds7.obsmtp.com (64.18.6.12)277,143,37620.46 
2216.183.239.10157,584,0264.25 
3www-vip10.dmz.fedex.com (199.81.204.50)38,929,2092.87 
4www.bbhcsd.org (208.108.152.49)32,861,1372.43 
566.184.207.18130,694,2442.27 
612.120.17.11026,379,9711.95 
712.120.109.11025,176,3811.86 
8host176.redtechnology.com (212.135.151.176)17,172,3291.27 
9205.177.95.2715,452,7191.14 
1066.77.9.20213,438,6960.99 



Top 10 sources, protocols and bytes
NoSourceProtocolConnectionsBytes%Comment
110.1.1.19SMTP/257,459277,143,37620.46 
210.1.100.138HTTP/803,643137,081,96710.12 
310.1.100.159RTSP/5540257,584,0264.25 
410.1.100.144HTTP/8030952,499,7293.88 
510.1.100.149HTTP/802,12849,297,4513.641 denials recorded on 11/13/2006 4:32:48 PM
610.1.100.143HTTP/801,75547,831,3233.53 
710.1.100.103HTTP/802,94544,871,2533.31 
810.1.90.101TCP/443 - ssl-https24041,659,6813.08 
910.1.100.142HTTP/801,60338,723,8142.86 
1010.1.100.120HTTP/801,43033,239,0752.45 

Top 10 sources, destinations, protocols and bytes
NoSourceDestinationProtocolConnectionsBytes%Comment
110.1.1.19outbounds7.obsmtp.com (64.18.6.12)SMTP/257,459277,143,37620.46 
210.1.100.159216.183.239.101RTSP/5540257,584,0264.25 
310.1.90.101www-vip10.dmz.fedex.com (199.81.204.50)TCP/443 - ssl-https7338,608,8852.85 
410.1.100.138www.bbhcsd.org (208.108.152.49)HTTP/808232,861,1372.43 
510.1.100.14466.184.207.181HTTP/800330,694,2442.27 
610.1.100.13812.120.17.110HTTP/800625,150,4981.86 
710.1.100.12912.120.109.110HTTP/800423,080,1911.70 
810.1.100.118205.177.95.27RTSP/5540115,452,7191.14 
910.1.100.138host176.redtechnology.com (212.135.151.176)TCP/443 - ssl-https3012,969,1220.96 
1010.1.1.1966.77.9.202HTTP/800111,572,1740.85 

Top 10 protocols
NoProtocolConnectionsBytes%Comment
1HTTP/8039,308816,457,38960.28 
2SMTP/257,459277,143,37620.46 
3TCP/443 - ssl-https3,394138,301,27410.21 
4RTSP/5540774,527,1505.50 
5TCP/1935138,737,9100.65 
6TCP/8080 - http proxy617,789,6180.58 
7UDP/53 - dns7,2976,146,9040.45 
8NETSHOW/1755014,440,6020.33 
9TCP/8200471,110,4900.08 
10TCP/880139811,3170.06 



Top 10 denied sources
NoSourceConnectionsFirst denial%Comment
1209.157.71.501611/13/2006 10:48:16 AM88.8948 denials recorded on 11/15/2006 3:20:29 PM
210.1.10.20111/13/2006 11:15:35 AM05.561 denials recorded on 11/14/2006 1:25:54 PM
310.1.100.1490111/13/2006 4:32:48 PM05.561 denials recorded on 11/13/2006 4:32:48 PM

Top 10 destinations for denied connections
NoDestinationConnectionsFirst denial%Comment
10.0.0.80 (80)1611/13/2006 10:48:16 AM88.89 
266.193.23.1130111/13/2006 11:15:35 AM05.56 
3web01-kly.opusnet.com (70.96.241.242)0111/13/2006 4:32:48 PM05.56 

Top 10 denied protocols
NoDenied protocolConnectionsFirst denial%Comment
1TCP/80 - http1711/13/2006 10:48:16 AM94.44 
2TCP0111/13/2006 11:15:35 AM05.56 



Top 10 denial reasons
NoDenial reasonConnectionsFirst denial%Comment
1Java applet blocked1611/13/2006 10:48:16 AM88.89 
2TCP half-open count 50 exceeded0111/13/2006 11:15:35 AM05.56 
3Invalid Window Scale option - Initiator scale 0 Responder scale 00111/13/2006 4:32:48 PM05.56 



Top 10 denied sources, destinations, protocols and reasons
NoSourceDestinationProtocolReasonConnectionsFirst denial%Comment
1209.157.71.500.0.0.80 (80)TCP/80 - httpJava applet blocked1611/13/2006 10:48:16 AM88.8948 denials recorded on 11/15/2006 3:20:29 PM
210.1.10.266.193.23.113TCPTCP half-open count 50 exceeded0111/13/2006 11:15:35 AM5.561 denials recorded on 11/14/2006 1:25:54 PM
310.1.100.149web01-kly.opusnet.com (70.96.241.242)TCP/80 - httpInvalid Window Scale option - Initiator scale 0 Responder scale 00111/13/2006 4:32:48 PM5.561 denials recorded on 11/13/2006 4:32:48 PM
1 denials recorded on 11/13/2006 4:32:48 PM
1 denials recorded on 11/13/2006 4:32:48 PM

Top 10 denied protocols and reasons
NoProtocolReasonDenials%Comment
1TCP/80 - httpJava applet blocked1688.89 
2TCPTCP half-open count 50 exceeded015.56 
3TCP/80 - httpInvalid Window Scale option - Initiator scale 0 Responder scale 0015.561 denials recorded on 11/13/2006 4:32:48 PM

Top 10 warning messages
NoSourceDestinationProtocolWarningCountFirst warning%Comment
166.193.23.11310.1.10.2TCPMax tcp half-open connections (50) exceeded0111/13/2006 11:15:34 AM100.001 denials recorded on 11/14/2006 1:25:54 PM

Other messages
NoCodeMessage sampleCountComment
1CRYPTO-3-QUERY_KEYQuerying key pair failed.2779 
2CRYPTO-4-IKMP_BAD_MESSAGEIKE message from 217.118.237.6 failed its sanity check or is malformed1375 
3VPN_HW-4-PACKET_ERRORslot: 0 Packet Encryption/Decryption error, Output Authentication error:srcadr=211.75.163.90,dstadr=144.232.212.18,size=168,handle=0x59D54 
4FW-4-UNBLOCK_HOSTNew TCP connections to host 66.193.23.113 no longer blocked1 
5CRYPTO-4-IKMP_PKT_OVERFLOWISAKMP message from 216.153.137.34 larger (-308757567) than the UDP packet length (92)1 
To assist us in improving the analyzer, please send the messages above to support@firegen.com and they will be added to the next release of Firegen.

Analysis details
Analysis start time11/15/2011 7:34:10 PM
Analysis duration0.38 minutes (22 seconds)
Analysis engine versionCisco IOSlog parser version: 0.01
FireGen30Service.exe - FireGen scheduler service: 3.0.0.0
Filtering criteriaAll entries
Excluded keywordsNone
Glossary
!!!Indicates that a high denials:connections ration has been detected. The current configured ratio is 3. The !!! indicates that the percentage of denials for that hour is bigger than 3 x the connections percentage. This indicates some unusual denial activity that may have to be investigated. The ratio can be configured on the Report Formats interface.
Other messagesThe Other messages represents a list of message not yet configured in the Firegen parser. Please send these messages to us (support@firegen.com) and we will add them in the next Firegen update. These messages are included in the list of message types but they are not yet fully understood by the analyzer.
  • Navigation