Altair Technologies - "sample" firewall log analysis for
06/10/2002 00:00:00 to 06/10/2002 23:59:59

Summary
ProcessEventsDuration
(in minutes)
Sent
(in MB)
Rcvd
(in MB)
Types
ProcessedReportedInfoNoticeWarningErrorAlertCriticalEmergency
cifsd330003      
dnsd116116000116      
eaglelogd220002      
ftpd440034      
gwcontrol1,0271,027000 1,024  3  
httpd749749271491,390674174    
kernel609609000 12597    
nbdgramd196196700196      
notifyd22000  1  1 
pingd2852853061919284 1    
readhawk77031,1134 1 2  
smtp3131324371963 3  
tcp-gsp11000  1    
tcpap-gsp28281002 1313   
udp-gsp885885301515833 52    
vultured11000   1   
Totals3,9463,9463744292,5472,1371,04374314810
Filtered0 

Research links

CIFSD - Back to top
No.TypeStartEndCountMessage
112106/10/02 09:24:1806/10/02 09:24:403Statistics: duration=nnn id=nnn src=192.168.0.231/pppp proto=cifs (Disconnected prematurely)


DNSD - Back to top
No.TypeStartEndCountMessage
112006/10/02 00:22:5506/10/02 23:52:3115dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 10.102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 128.9.64.26/No response, 198.32.1.116/No response)
212006/10/02 00:13:3006/10/02 23:59:4614dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 142.0.42.10.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
312006/10/02 00:12:4906/10/02 03:39:499dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 10.102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 198.32.1.116/No response, 128.9.64.26/No response)
412006/10/02 03:36:0406/10/02 23:42:536dnsd Info: Failed to handle request from 172.32.10.11 for StartOfAuthority for 102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 128.9.64.26/No response, 198.32.1.116/No response)
512006/10/02 19:45:3906/10/02 20:24:386dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 12.102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 128.9.64.26/No response, 198.32.1.116/No response)
612006/10/02 00:58:3206/10/02 03:43:416dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 142.0.42.10.in-addr.arpa. - no progress possible (198.32.1.116/No response, 128.9.64.26/No response)
712006/10/02 00:11:0306/10/02 03:14:014dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 40.10.18.172.in-addr.arpa. - no progress possible (198.32.1.116/No response, 128.9.64.26/No response)
812006/10/02 00:33:0706/10/02 23:28:124dnsd Info: Failed to handle request from 172.32.10.21 for DomainName for 71.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
912006/10/02 00:28:3806/10/02 22:28:434dnsd Info: Failed to handle request from 172.32.10.21 for DomainName for 113.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
1012006/10/02 19:46:4206/10/02 21:36:433dnsd Info: Failed to handle request from 172.32.10.21 for DomainName for 198.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
1112006/10/02 18:28:1306/10/02 18:28:133dnsd Info: Refusing request from 216.33.87.9 (on interface 34.28.69.34) for Address for . - not authoritative and not recursing for this request
1212006/10/02 01:16:3106/10/02 23:38:383dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 207.0.42.10.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
1312006/10/02 00:12:3106/10/02 03:15:313dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 128.10.18.172.in-addr.arpa. - no progress possible (198.32.1.116/No response, 128.9.64.26/No response)
1412006/10/02 16:57:4706/10/02 16:57:473dnsd Info: Refusing request from 216.33.87.8 (on interface 34.28.69.34) for Address for . - not authoritative and not recursing for this request
1512006/10/02 00:14:0106/10/02 23:37:053dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 205.0.42.10.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
1612006/10/02 01:35:3806/10/02 03:47:523dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 11.102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 198.32.1.116/No response, 128.9.64.26/No response)
1712006/10/02 01:23:3706/10/02 19:43:393dnsd Info: Failed to handle request from 172.32.10.21 for DomainName for 113.10.18.172.in-addr.arpa. - no progress possible (198.32.1.116/No response, 128.9.64.26/No response)
1812006/10/02 00:23:0106/10/02 19:42:052dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 113.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
1912006/10/02 09:30:3106/10/02 09:31:422dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 2.221.5.209.in-addr.arpa. - no progress possible (ntserver.microsoft.ca./No NS address, ns.sprint-canada.net./Lame)
2012006/10/02 20:40:3906/10/02 23:41:302dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 11.102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 128.9.64.26/No response, 198.32.1.116/No response)
2112006/10/02 02:14:4306/10/02 02:14:432dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 12.102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 198.32.1.116/No response, 128.9.64.26/No response)
2212006/10/02 00:26:0106/10/02 22:48:052dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 41.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
2312006/10/02 19:30:0606/10/02 20:31:052dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 40.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
2412006/10/02 19:31:3606/10/02 20:32:362dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 128.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
2512006/10/02 01:35:3006/10/02 01:37:162dnsd Info: Failed to handle request from 172.32.10.11 for StartOfAuthority for 102.17.172.in-addr.arpa. - no progress possible (198.41.0.11/No response, 198.32.1.116/No response, 128.9.64.26/No response)
2612006/10/02 01:03:4106/10/02 01:03:411dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 10.10.18.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
2712006/10/02 20:42:2106/10/02 20:42:211dnsd Info: Failed to handle request from 172.32.10.11 for StartOfAuthority for 102.17.172.in-addr.arpa. - failsafe timeout expired (198.41.0.11/No response, 128.9.64.26/No response, 198.32.1.116/No response)
2812006/10/02 00:32:4506/10/02 00:32:451dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 10.102.17.172.in-addr.arpa. - no progress possible (128.9.64.26/No response, 198.32.1.116/No response)
2912006/10/02 01:23:3706/10/02 01:23:371dnsd Info: Failed to handle request from 192.168.0.156 for DomainName for 113.10.18.172.in-addr.arpa. - no progress possible (198.32.1.116/No response, 128.9.64.26/No response)
3012006/10/02 20:42:0506/10/02 20:42:051dnsd Info: Failed to handle request from 127.0.0.1 for DomainName for 12.102.17.172.in-addr.arpa. - failsafe timeout expired (198.41.0.11/No response, 128.9.64.26/No response, 198.32.1.116/No response)
!!!There were 33 messages to be reported but the listing is limited to 30.


EAGLELOGD - Back to top
No.TypeStartEndCountMessage
110806/10/02 00:00:0106/10/02 00:00:011starting new log file. UTC offset is -0500, Year is 2002, Raptor Security Gateway is 6.5, OS is "NT 4.0 (Build 1381: Service Pack 5)", Platform is "Intel x86"
210712/25/02 00:00:0312/25/02 00:00:031closing log file


FTPD - Back to top
No.TypeStartEndCountMessage
112106/10/02 12:35:5806/10/02 12:35:581Statistics: duration=nnn id=nnn rid=187ti rcvd=nnn srcif=Vpn4 src=10.42.0.142/pppp cldst=161.69.2.7/17291 svsrc=64.39.69.34/pppp dst=161.69.2.7/3376 op=LIST arg=/pub/antivirus/datfiles/4.x result="226 Transfer complete." proto=ftp-data
212106/10/02 12:35:5706/10/02 12:35:571Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=10.42.0.142/pppp svsrc=64.39.69.34/pppp dstif=Vpn3 dst=161.69.2.7/21 proto=ftp rule=1
312106/10/02 12:35:5706/10/02 12:35:571Statistics: duration=nnn id=nnn rid=187tf rcvd=nnn srcif=Vpn4 src=10.42.0.142/pppp cldst=161.69.2.7/17597 svsrc=64.39.69.34/pppp dst=161.69.2.7/3364 op=LIST arg=/pub/antivirus/datfiles/4.x result="226 Transfer complete." proto=ftp-data
412106/10/02 12:35:5706/10/02 12:35:571Statistics: duration=nnn id=nnn rid=187tf rcvd=nnn srcif=Vpn4 src=10.42.0.142/pppp cldst=161.69.2.7/15088 svsrc=64.39.69.34/pppp dst=161.69.2.7/3370 op=RETR arg=/pub/antivirus/datfiles/4.x/DELTA.INI result="226 Transfer complete." proto=ftp-data


GWCONTROL - Back to top
No.TypeStartEndCountMessage
120106/10/02 00:00:5706/10/02 23:59:46196nbdgram: access denied for 192.168.0.142 to 199.166.214.133 [default rule] [no rules found]
220106/10/02 00:34:3306/10/02 23:52:468953/udp: access denied for 172.32.10.11 to a.root-servers.net [default rule] [no rules found]
320106/10/02 03:48:1206/10/02 23:52:466553/udp: access denied for 172.32.10.11 to m.root-servers.net [default rule] [no rules found]
420106/10/02 00:34:3906/10/02 23:52:476353/udp: access denied for 172.32.10.11 to d.root-servers.net [default rule] [no rules found]
520106/10/02 00:34:3606/10/02 23:52:476253/udp: access denied for 172.32.10.11 to b.root-servers.net [default rule] [no rules found]
620106/10/02 00:34:3606/10/02 23:52:476053/udp: access denied for 172.32.10.11 to c.root-servers.net [default rule] [no rules found]
720106/10/02 00:36:1706/10/02 19:41:215453/udp: access denied for 172.32.10.12 to blackhole.isi.edu [default rule] [no rules found]
820106/10/02 00:34:3306/10/02 19:39:505353/udp: access denied for 172.32.10.11 to blackhole.isi.edu [default rule] [no rules found]
920106/10/02 01:35:1106/10/02 22:42:164953/udp: access denied for 172.32.10.11 to 192.203.230.10 [default rule] [no rules found]
1020106/10/02 03:48:1206/10/02 23:53:024953/udp: access denied for 172.32.10.11 to k.root-servers.net [default rule] [no rules found]
1120106/10/02 03:48:1206/10/02 19:52:484853/udp: access denied for 172.32.10.11 to f.root-servers.net [default rule] [no rules found]
1220106/10/02 03:48:1206/10/02 19:52:484853/udp: access denied for 172.32.10.11 to rns.arl.mil [default rule] [no rules found]
1320106/10/02 03:48:1206/10/02 19:52:484753/udp: access denied for 172.32.10.11 to j.root-servers.net [default rule] [no rules found]
1420106/10/02 03:48:1206/10/02 19:52:484753/udp: access denied for 172.32.10.11 to i.root-servers.net [default rule] [no rules found]
1520106/10/02 03:48:1206/10/02 19:52:484753/udp: access denied for 172.32.10.11 to G.ROOT-SERVERS.NET [default rule] [no rules found]
1620106/10/02 03:48:1206/10/02 11:52:102653/udp: access denied for 172.32.10.11 to l.root-servers.net [default rule] [no rules found]
1720106/10/02 00:34:3906/10/02 23:41:311853/udp: access denied for 172.32.10.11 to E.ROOT-SERVERS.NET [default rule] [no rules found]
1820106/10/02 04:50:0406/10/02 20:08:062http: access denied for sntc01hpov.exodus.net to samplefw.ffhexodustor.com [default rule] [no rules found]
1950106/10/02 00:10:2406/10/02 00:10:241access from 209.47.167.99 to 172.17.102.10 [rule id 6]: over 5 tries in 1 hour
2020106/10/02 01:45:4806/10/02 01:45:481http: access denied for 62.254.209.4 to samplefw.ffhexodustor.com [default rule] [no rules found]
2150106/10/02 00:10:2406/10/02 00:10:241access from 209.47.167.99 to 172.17.102.10 [rule id 6]: over 1020 tries in 7 days
2250106/10/02 00:10:2406/10/02 00:10:241access from 209.47.167.99 to 172.17.102.10 [rule id 6]: over 367 tries in 1 day


HTTPD - Back to top
No.TypeStartEndCountMessage
112106/10/02 00:00:4806/10/02 23:56:52573Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=34.28.65.8/pppp cldst=34.28.69.36/80 svsrc=34.28.65.8/pppp dstif=Vpn6 dst=172.32.10.10/80 op=GET arg=http://172.32.10.10/ result="200 OK" proto=http rule=2
231006/10/02 04:20:2406/10/02 20:06:0460user.producerpartners.com 208.3.107.170: can't verify reverse address
331006/10/02 02:13:5806/10/02 20:41:0514user.producerpartners.com 208.3.107.171: can't verify reverse address
412106/10/02 12:38:5206/10/02 12:47:017Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.206.240.100/pppp cldst=34.28.69.34/443 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/443 proto=http-https state=rsa/rc4_128_md5 rule=11 (Unknown error)
512106/10/02 12:36:5706/10/02 12:38:565Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.206.240.100/pppp cldst=34.28.69.34/443 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/443 proto=http-https state=rsa/rc4_128_md5 rule=11
612106/10/02 09:31:5706/10/02 09:37:254Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=209.5.221.2/pppp cldst=34.28.69.34/443 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/443 proto=http-https state=rsa/rc4_128_md5 rule=11
712106/10/02 06:11:3706/10/02 18:11:342Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=209.205.38.34/pppp cldst=64.39.69.33/80 svsrc=209.205.38.34/pppp dstif=Vpn6 dst=172.32.10.11/80 op=GET arg=http://intrapxy1.altairtech.ca/ffhtoronto/images/logon_top.jpg result="304 Not Modified" proto=http rule=2
812106/10/02 02:14:3106/10/02 14:14:082Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.171/pppp cldst=216.63.107.150/80 svsrc=208.3.107.171/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/logon_top.jpg result="304 Not Modified" proto=http rule=2
912106/10/02 07:44:2606/10/02 19:45:292Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/transparent.gif result="304 Not Modified" proto=http rule=2
1012106/10/02 07:45:0506/10/02 19:45:082Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/help/portal_help_top.htm result="304 Not Modified" proto=http rule=2
1112106/10/02 07:44:4506/10/02 19:45:232Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/help/menu.htm result="304 Not Modified" proto=http rule=2
1212106/10/02 08:05:0606/10/02 20:06:042Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/corechange.gif result="304 Not Modified" proto=http rule=2
1312106/10/02 04:20:2406/10/02 16:21:262Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/portalfunctions/WebAlign/images/header_priority.gif result="304 Not Modified" proto=http rule=2
1412106/10/02 08:05:2106/10/02 20:06:032Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/logon_left.jpg result="304 Not Modified" proto=http rule=2
1512106/10/02 07:45:3506/10/02 19:45:132Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/logon_mid_right.gif result="304 Not Modified" proto=http rule=2
1612106/10/02 04:50:0406/10/02 20:08:062Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.33.139.166/pppp dst=34.28.69.34/80 op=HEAD arg=/ result="403 Forbidden" proto=http (request denied by gwcontrol)
1712106/10/02 08:40:1306/10/02 20:41:102Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.171/pppp cldst=216.63.107.150/80 svsrc=208.3.107.171/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/logon_bottom.jpg result="304 Not Modified" proto=http rule=2
1812106/10/02 07:45:3006/10/02 19:44:592Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/controls/windowssso.cab result="304 Not Modified" proto=http rule=2
1912106/10/02 07:45:2006/10/02 19:45:032Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/logon_mid_left.gif result="304 Not Modified" proto=http rule=2
2012106/10/02 07:45:1506/10/02 19:45:032Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/help/user_interface.gif result="304 Not Modified" proto=http rule=2
2112106/10/02 08:23:0206/10/02 20:24:002Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.171/pppp cldst=216.63.107.150/80 svsrc=208.3.107.171/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/login.css result="304 Not Modified" proto=http rule=2
2212106/10/02 07:46:2506/10/02 19:45:292Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/default/window_change_tab.gif result="304 Not Modified" proto=http rule=2
2312106/10/02 07:45:5006/10/02 19:45:132Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/default/header_logout.gif result="304 Not Modified" proto=http rule=2
2412106/10/02 04:20:2606/10/02 16:21:262Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/default/default.css result="304 Not Modified" proto=http rule=2
2512106/10/02 06:07:2206/10/02 18:08:252Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.171/pppp cldst=216.63.107.150/80 svsrc=208.3.107.171/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/logon_background.gif result="304 Not Modified" proto=http rule=2
2612106/10/02 07:46:1006/10/02 19:45:282Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/default/header_tab_edge.gif result="304 Not Modified" proto=http rule=2
2712106/10/02 07:46:2006/10/02 19:45:292Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/default/window_frame_background.gif result="304 Not Modified" proto=http rule=2
2812106/10/02 02:14:3006/10/02 14:14:052Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.171/pppp cldst=216.63.107.150/80 svsrc=208.3.107.171/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/images/mi2g.gif result="304 Not Modified" proto=http rule=2
2912106/10/02 07:44:4006/10/02 19:45:232Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.3.107.170/pppp cldst=216.63.107.150/80 svsrc=208.3.107.170/pppp dstif=Vpn6 dst=172.32.10.12/80 op=GET arg=http://intrapxy2.altairtech.ca/ffhtoronto/schemes/default/window_maximize.gif result="304 Not Modified" proto=http rule=2
3012106/10/02 06:11:2806/10/02 18:11:342Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=209.205.38.34/pppp cldst=64.39.69.33/80 svsrc=209.205.38.34/pppp dstif=Vpn6 dst=172.32.10.11/80 op=GET arg=http://intrapxy1.altairtech.ca/ffhtoronto/images/mi2g.gif result="304 Not Modified" proto=http rule=2
!!!There were 51 messages to be reported but the listing is limited to 30.


KERNEL - Back to top
No.TypeStartEndCountMessage
130106/10/02 00:02:0106/10/02 23:58:11545Internal warning: TCP session [state: 3, inactive for nn seconds] between 34.28.65.8/pppp and 34.28.69.36/80 timed out due to inactivity
222606/10/02 00:34:2206/10/02 13:30:5412IP packet dropped (sntc01hpov.exodus.net[216.33.139.166]->mail.altairtech.ca[34.28.69.34]: Protocol=ICMP[Mask request]): Unusual or disallowed ICMP (received on interface 34.28.69.34)
330106/10/02 06:12:4106/10/02 18:12:416Internal warning: TCP session [state: 3, inactive for nn seconds] between 209.205.38.34/pppp and 64.39.69.33/80 timed out due to inactivity
430106/10/02 00:42:2406/10/02 17:44:335Internal warning: TCP session [state: 3, inactive for nn seconds] between 216.52.49.35/pppp and 34.28.69.34/25 timed out due to inactivity
530106/10/02 09:32:3106/10/02 09:38:354Internal warning: TCP session [state: 3, inactive for nn seconds] between 209.5.221.2/pppp and 34.28.69.34/443 timed out due to inactivity
630106/10/02 04:51:2706/10/02 20:08:332Internal warning: TCP session [state: 3, inactive for nn seconds] between 216.33.139.166/pppp and 34.28.69.34/80 timed out due to inactivity
730106/10/02 12:37:2406/10/02 12:42:002Internal warning: TCP session [state: 3, inactive for nn seconds] between 216.206.240.100/pppp and 34.28.69.34/443 timed out due to inactivity
830106/10/02 12:42:3306/10/02 12:42:331Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/4528 timed out due to inactivity
930106/10/02 17:18:0506/10/02 17:18:051Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/9468 timed out due to inactivity
1030106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.141/pppp and 24.0.95.25/25 timed out due to inactivity
1130106/10/02 20:50:4006/10/02 20:50:401Internal warning: TCP session [state: 3, inactive for nn seconds] between 216.208.64.162/pppp and 34.28.69.34/25 timed out due to inactivity
1230106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 24.0.95.25/pppp and 34.28.69.34/4594 timed out due to inactivity
1330106/10/02 09:04:1806/10/02 09:04:181Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/1025 timed out due to inactivity
1430106/10/02 13:55:2506/10/02 13:55:251Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/5844 timed out due to inactivity
1530106/10/02 09:38:3506/10/02 09:38:351Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/1604 timed out due to inactivity
1630106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.141/pppp and 216.33.238.136/25 timed out due to inactivity
1730106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 216.33.238.136/pppp and 34.28.69.34/4597 timed out due to inactivity
1830106/10/02 07:46:2606/10/02 07:46:261Internal warning: TCP session [state: 3, inactive for nn seconds] between 172.32.10.10/pppp and 34.28.65.8/8608 timed out due to inactivity
1930106/10/02 00:42:2406/10/02 00:42:241Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/1177 timed out due to inactivity
2030106/10/02 09:34:3406/10/02 09:34:341Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/1567 timed out due to inactivity
2130106/10/02 09:34:3406/10/02 09:34:341Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/1556 timed out due to inactivity
2230106/10/02 07:46:2606/10/02 07:46:261Internal warning: TCP session [state: 3, inactive for nn seconds] between 172.32.10.10/pppp and 34.28.65.8/8622 timed out due to inactivity
2330106/10/02 07:47:2406/10/02 07:47:241Internal warning: TCP session [state: 3, inactive for nn seconds] between 172.32.10.10/pppp and 34.28.65.8/8631 timed out due to inactivity
2430106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.141/pppp and 209.226.175.82/25 timed out due to inactivity
2530106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 209.82.62.48/pppp and 34.28.69.34/4590 timed out due to inactivity
2630106/10/02 01:47:0406/10/02 01:47:041Internal warning: TCP session [state: 3, inactive for nn seconds] between 62.254.209.4/pppp and 34.28.69.34/80 timed out due to inactivity
2730106/10/02 17:44:3306/10/02 17:44:331Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/9954 timed out due to inactivity
2830106/10/02 12:37:2406/10/02 12:37:241Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.142/pppp and 192.168.0.130/4451 timed out due to inactivity
2930106/10/02 19:19:4606/10/02 19:19:461Internal warning: TCP session [state: 3, inactive for nn seconds] between 172.32.10.10/pppp and 34.28.65.8/2727 timed out due to inactivity
3030106/10/02 12:47:0106/10/02 12:47:011Internal warning: TCP session [state: 3, inactive for nn seconds] between 192.168.0.141/pppp and 209.82.62.48/25 timed out due to inactivity
!!!There were 40 messages to be reported but the listing is limited to 30.


NBDGRAMD - Back to top
No.TypeStartEndCountMessage
112106/10/02 00:00:5706/10/02 23:59:46195Statistics: duration=nnn id=nnn srcif=Vpn4 src=192.168.0.142/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=199.166.214.133/pppp proto=nbdgram (Not authorized)
212106/10/02 01:43:1706/10/02 01:43:171Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn4 src=192.168.0.142/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=199.166.214.133/pppp proto=nbdgram (Not authorized)


NOTIFYD - Back to top
No.TypeStartEndCountMessage
130806/10/02 15:42:1206/10/02 15:42:121Warning: can't lookup host mail.altairtech.ca
260606/10/02 15:42:1206/10/02 15:42:121failed to notify: transport=Mail, priority=Error, (adrian@altairtech.ca, 0)


PINGD - Back to top
No.TypeStartEndCountMessage
112106/10/02 00:03:1006/10/02 23:58:21283Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.33.139.166 dst=34.28.69.34 proto=ping (Implicitly allowed -- local interface)
234306/10/02 09:30:3706/10/02 09:30:371Interfaces Warning: Unable to determine tunnel information for destination address 34.28.69.40 - is the system local and down? -- test connectivity with ping
312106/10/02 09:30:3706/10/02 09:30:371Statistics: duration=nnn id=nnn sent=nnn src=209.5.221.2 dst=34.28.69.40 proto=ping (failed to get call addressing information)


READHAWK - Back to top
No.TypeStartEndCountMessage
151206/10/02 14:56:1106/10/02 14:56:111Unauthorized remote connect attempt from host 216.208.64.162 (no entry in remkeys -- access to remote logging functions are denied)Jun 10 14:57:47.359 samplefw httpd: 121 Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=34.28.65.8/pppp cldst=34.28.69.36/80 svsrc=34.28.65.8/pppp dstif=Vpn6 dst=172.32.10.10/80 op=GET arg=http://172.32.10.10/ result="200 OK" proto=http rule=2
211506/10/02 01:03:1806/10/02 01:03:181remotelog: remote management connection from host 172.18.10.10
334306/10/02 11:40:1806/10/02 11:40:181readhawk Warning: Key negotiation failure -- probably incorrect password
411506/10/02 11:40:1706/10/02 11:40:171readhawk: remote management connection from host 172.18.10.39
551206/10/02 14:54:0506/10/02 14:54:051Unauthorized remote connect attempt from host 216.208.64.162 (no entry in remkeys -- access to remote management functions are denied)
612106/10/02 01:03:4806/10/02 01:03:481Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=172.18.10.10/pppp dst=192.168.0.130/417 proto=remotelog
711606/10/02 01:03:4806/10/02 01:03:481remotelog: remote management completed


SMTP - Back to top
No.TypeStartEndCountMessage
112106/10/02 03:43:0106/10/02 09:44:443Statistics: duration=nnn id=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=63.79.76.132/pppp proto=smtp rule=1 (Cannot connect to server)
222806/10/02 03:43:5106/10/02 09:45:333smtp: can't connect to gateway.kellogg.com port 25 (Connection timed out.)
312106/10/02 03:43:5106/10/02 09:45:333Statistics: duration=nnn id=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.108.149.20/pppp proto=smtp rule=1 (Cannot connect to server)
422806/10/02 03:43:0106/10/02 09:44:443smtp: can't connect to 63.79.76.132 port 25 (Connection refused.)
512106/10/02 13:55:1806/10/02 13:55:181Statistics: duration=nnn user=<> id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=208.222.100.67/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" arg=<0037153511818c0WEB012@web012.intranets.com> result="250 2.6.0 <0037153511818c0WEB012@web012.intranets.com> Queued mail for delivery" proto=smtp rule=11
612106/10/02 09:03:0306/10/02 09:03:031Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.52.49.35/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" arg=<20001224135859.18045.qmail@web5505.mail.yahoo.com> result="250 2.6.0 <20001224135859.18045.qmail@web5505.mail.yahoo.com> Queued mail for delivery" proto=smtp rule=11
712106/10/02 20:49:2806/10/02 20:49:281Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.208.64.162/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 2 recips" arg=<200012250144.UAA11151@effhsun01.acme.com> result="250 2.6.0 <200012250144.UAA11151@effhsun01.acme.com> Queued mail for delivery" proto=smtp rule=11
831006/10/02 14:27:3906/10/02 14:27:391nameservices.net 216.117.150.153: can't verify reverse address - mismatched reverse lookup: 208.234.1.33
912106/10/02 00:41:2906/10/02 00:41:291Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.52.49.35/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" result="250 2.6.0 Queued mail for delivery" proto=smtp rule=11
1012106/10/02 10:07:3306/10/02 10:07:331Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=204.68.24.28/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" arg=<20001224150409.18818.qmail@nw128.netaddress.usa.net> result="250 2.6.0 <20001224150409.18818.qmail@nw128.netaddress.usa.net> Queued mail for delivery" proto=smtp rule=11
1112106/10/02 17:16:2906/10/02 17:16:291Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.52.49.35/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" arg=<200012242212.eBOMCmF63404@hub.org> result="250 2.6.0 <200012242212.eBOMCmF63404@hub.org> Queued mail for delivery" proto=smtp rule=11
1212106/10/02 12:42:0406/10/02 12:42:041Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.52.49.35/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" arg=<20001224172412.16629.qmail@sun01293.dn.net> result="250 2.6.0 <20001224172412.16629.qmail@sun01293.dn.net> Queued mail for delivery" proto=smtp rule=11
1351406/10/02 05:20:3106/10/02 05:20:311smtpd: Unauthorized SMTP protocol: command 'WIZ' from gateway.tescom.co.uk ([194.205.85.2])Jun 10 05:21:40.593 samplefw httpd: 121 Statistics: duration=nnn id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=34.28.65.8/pppp cldst=34.28.69.36/80 svsrc=34.28.65.8/pppp dstif=Vpn6 dst=172.32.10.10/80 op=GET arg=http://172.32.10.10/ result="200 OK" proto=http rule=2
1412106/10/02 12:45:4006/10/02 12:45:401Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34/pppp dstif=Vpn3 dst=216.129.36.12/25 op="To 1 recips" arg= result="250 MAA19911 Message accepted for delivery" proto=smtp rule=1
1550306/10/02 10:17:4806/10/02 10:17:481poptart.svr.home.net 24.0.26.24: reverse address 24.0.26.112,24.0.26.113 doesn't match -- denied
1634306/10/02 19:17:3206/10/02 19:17:321smtpd Warning: Sender from [10.42.0.141] tried to send to '' - Bad recipient format -- possible relay attempt
1712106/10/02 12:45:3906/10/02 12:45:391Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34/pppp dstif=Vpn3 dst=209.82.62.48/25 op="To 1 recips" arg= result="250 NAA17808 Message accepted for delivery" proto=smtp rule=1
1812106/10/02 12:45:3906/10/02 12:45:391Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34/pppp dstif=Vpn3 dst=24.0.95.25/25 op="To 1 recips" arg= result="250 JAA10307 Message accepted for delivery" proto=smtp rule=1
1931006/10/02 14:27:3906/10/02 14:27:391nameservices.net 216.117.150.153: can't verify reverse address - lookup does not include original address: 208.234.1.33
2012106/10/02 17:43:2406/10/02 17:43:241Statistics: duration=nnn user=<> id=nnn sent=nnn rcvd=nnn srcif=Vpn3 src=216.52.49.35/pppp cldst=34.28.69.34/25 svsrc=192.168.0.130/pppp dstif=Vpn4 dst=192.168.0.142/25 op="To 1 recips" arg=<200012242236.OAA11994@p6.webshots.com> result="250 2.6.0 <200012242236.OAA11994@p6.webshots.com> Queued mail for delivery" proto=smtp rule=11
2112106/10/02 12:45:3906/10/02 12:45:391Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34/pppp dstif=Vpn3 dst=209.226.175.82/25 op="To 1 recips" arg= result="250 Message received: 20001224174217.KFZP13021.tomts10-srv.bellnexxia.net@mail.altairtech.ca" proto=smtp rule=1
2212106/10/02 12:45:4006/10/02 12:45:401Statistics: duration=nnn user= id=nnn sent=nnn rcvd=nnn srcif=Vpn4 src=192.168.0.141/pppp svsrc=34.28.69.34/pppp dstif=Vpn3 dst=216.33.238.136/25 op="To 2 recips" arg= result="250 Requested mail action okay, completed" proto=smtp rule=1
2350306/10/02 10:42:1206/10/02 10:42:121poptart.svr.home.net 24.0.26.24: reverse address 24.0.26.113,24.0.26.112 doesn't match -- denied


TCP-GSP - Back to top
No.TypeStartEndCountMessage
134406/10/02 08:53:1606/10/02 08:53:161110/tcp: Non-transparent call from trt-on54-072.netcom.ca


TCPAP-GSP - Back to top
No.TypeStartEndCountMessage
140106/10/02 08:34:4406/10/02 08:34:446Internal error: attempt to release a lock that is not held. Deadlock may result. (padlock_release, caller id string: "..\dgramdispatch.c 1198")
231006/10/02 23:12:3706/10/02 23:12:376net233.ghaps.org 216.93.78.233: can't verify reverse address
340106/10/02 08:34:4406/10/02 08:34:445Internal error: cannot create thread (Not enough storage is available to process this command. )
430106/10/02 08:34:4406/10/02 08:34:445Internal warning: could not queue packet on authorization queue
534306/10/02 08:34:4406/10/02 08:34:442Interfaces Warning: Unable to determine tunnel information for destination address 64.39.69.36 - is the system local and down? -- test connectivity with ping
640106/10/02 08:34:4406/10/02 08:34:441Internal error: Process terminating with signal 11 [Access violation at 0x77f6ce0c: eax=0x0, ebx=0x477800, ecx=0x1, edx=0x77fa75c0, esi=0x349a9c, edi=0x0, ebp=0x16c9f960, esp=0x16c9f900, eip=0x77f6ce0c]
712106/10/02 08:34:4406/10/02 08:34:441Statistics: duration=nnn id=nnn src=212.32.48.197/pppp dst=64.39.69.36/941 proto=941/tcp (failed to get call addressing information)
812106/10/02 08:34:4406/10/02 08:34:441Statistics: duration=nnn id=nnn src=212.32.48.197/pppp dst=64.39.69.36/1544 proto=1544/tcp (failed to get call addressing information)
940106/10/02 08:34:4406/10/02 08:34:441Internal error: Process terminating with signal 11 [Access violation at 0x77f6ce0c: eax=0x0, ebx=0x477800, ecx=0x0, edx=0x349a9c, esi=0x349a9c, edi=0x0, ebp=0x16d9f960, esp=0x16d9f900, eip=0x77f6ce0c]


UDP-GSP - Back to top
No.TypeStartEndCountMessage
112106/10/02 00:34:3306/10/02 21:40:2580Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.41.0.4/pppp proto=53/udp (Not authorized)
212106/10/02 00:34:3906/10/02 23:52:4759Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.8.10.90/pppp proto=53/udp (Not authorized)
312106/10/02 00:34:3906/10/02 23:42:3259Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.203.230.10/pppp proto=53/udp (Not authorized)
412106/10/02 03:51:2606/10/02 23:42:1554Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=202.12.27.33/pppp proto=53/udp (Not authorized)
512106/10/02 00:36:1706/10/02 19:41:2154Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.12/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.9.64.26/pppp proto=53/udp (Not authorized)
612106/10/02 00:34:3306/10/02 19:39:5053Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.9.64.26/pppp proto=53/udp (Not authorized)
712106/10/02 00:34:3606/10/02 23:52:4753Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.9.0.107/pppp proto=53/udp (Not authorized)
812106/10/02 00:34:3606/10/02 23:52:4752Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.33.4.12/pppp proto=53/udp (Not authorized)
931006/10/02 01:35:1106/10/02 23:52:5051norad.arc.nasa.gov 192.203.230.10: can't verify reverse address
1012106/10/02 03:51:2006/10/02 19:48:3147Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.63.2.53/pppp proto=53/udp (Not authorized)
1112106/10/02 03:51:2306/10/02 23:53:0247Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=193.0.14.129/pppp proto=53/udp (Not authorized)
1212106/10/02 03:51:2306/10/02 15:52:2746Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.41.0.10/pppp proto=53/udp (Not authorized)
1312106/10/02 03:51:2006/10/02 19:48:2746Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.5.5.241/pppp proto=53/udp (Not authorized)
1412106/10/02 03:51:2006/10/02 19:48:3146Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.112.36.4/pppp proto=53/udp (Not authorized)
1512106/10/02 03:51:2306/10/02 15:52:2745Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.36.148.17/pppp proto=53/udp (Not authorized)
1612106/10/02 03:51:2606/10/02 11:52:1025Statistics: duration=nnn id=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.32.64.12/pppp proto=53/udp (Not authorized)
1712106/10/02 01:35:1106/10/02 23:52:469Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.33.4.12/pppp proto=53/udp (Not authorized)
1812106/10/02 01:35:1106/10/02 23:52:469Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.9.0.107/pppp proto=53/udp (Not authorized)
1912106/10/02 01:35:1106/10/02 23:41:319Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.203.230.10/pppp proto=53/udp (Not authorized)
2012106/10/02 03:48:1206/10/02 23:52:469Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=202.12.27.33/pppp proto=53/udp (Not authorized)
2112106/10/02 01:35:1106/10/02 23:52:469Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.41.0.4/pppp proto=53/udp (Not authorized)
2212106/10/02 01:35:1106/10/02 23:41:318Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.8.10.90/pppp proto=53/udp (Not authorized)
2312106/10/02 03:48:1206/10/02 19:52:482Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=128.63.2.53/pppp proto=53/udp (Not authorized)
2412106/10/02 03:48:1206/10/02 19:52:482Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.36.148.17/pppp proto=53/udp (Not authorized)
2512106/10/02 03:48:1206/10/02 19:52:482Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=193.0.14.129/pppp proto=53/udp (Not authorized)
2612106/10/02 03:48:1206/10/02 19:52:482Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.5.5.241/pppp proto=53/udp (Not authorized)
2712106/10/02 03:48:1206/10/02 19:52:482Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=192.112.36.4/pppp proto=53/udp (Not authorized)
2812106/10/02 03:48:1206/10/02 19:52:482Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.41.0.10/pppp proto=53/udp (Not authorized)
2912106/10/02 03:48:1206/10/02 03:48:121Statistics: duration=nnn id=nnn sent=nnn srcif=Vpn6 src=172.32.10.11/pppp svsrc=34.28.69.34 dstif=Vpn3 dst=198.32.64.12/pppp proto=53/udp (Not authorized)
3034306/10/02 09:30:3706/10/02 09:47:311Interfaces Warning: Unable to determine tunnel information for destination address 34.28.69.40 - is the system local and down? -- test connectivity with ping
!!!There were 31 messages to be reported but the listing is limited to 30.


VULTURED - Back to top
No.TypeStartEndCountMessage
140106/10/02 02:34:2806/10/02 02:34:281Internal error: can't get process name for process 281 (2: The system cannot find the file specified. )


Analysis duration: 2 seconds.
Log lines analyzed: 3,946
Analysis speed: 1,973 lines/second.

Back to Content