Acme Inc. - "cerber" firewall log analysis for the period
Fri Jan 24 00:00:00 2003 to Fri Jan 24 23:59:59 2003

FirewallsSectionsFirst messageLast message
172.17.250.4SummaryMessage typesDetailsDestinationsSourcesProtocolsDenialsTraffic01/24/03 00:00:0001/24/03 00:03:41

Research links
TCP/IP Protocol
PIX message code
Whois
Send your comments or suggestions to the FireGen developers!
 
Glossary
Analysis performance

Keywords to include
Keywords to exclude

Analyzed log(s)Log size (kb)Log entriesLog type
C:\Program Files\FireGenPix\Sample\kiwilogISO-2003-01-24.log100.28576Kiwi syslog - format ISO - (Tab delimited) with no PIX time stamp

Summary for the 172.17.250.4 firewall. Back to top
LevelSeverityDescriptionTotalReportedExcluded
1AlertImmediate action needed330
2CriticalCritical condition220
3ErrorError condition880
4WarningWarning condition27270
5NotificationNormal but significant condition220
6InformationalInformational message only5325320
7DebuggingAppears during debugging only220
  Total5765760


Message types distribution for the 172.17.250.4 firewall. Back to top
NoCodeTotalExample
11-1010021(Primary) Bad failover cable.
21-1050011(Primary) Disabling failover.
31-1060221Deny protocol connection spoof from 203.45.122.5 to 216.208.34.22 on interface inside
42-1100031No interface is configured (with name out_vpn).
52-7090071Configuration replication failed for command write memory
63-1060116Deny inbound (No xlate) tcp src outside:80.142.137.204/nnnn dst outside:216.13.68.122/21
73-2020011Out of address translation slots!
83-2110031CPU utilization for time seconds = %75
94-10602326Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.115/21 by access-group "acl_out"
104-3090041Manager session limit exceeded. Connection request from 192.168.1.5 on interface inside
115-1110061Console Login from user at 192.168.1.4
125-1990011PIX reload command executed from telnet (192.168.1.4).
136-10601517Deny TCP (no connection) from 10.42.0.141/25 to 172.18.10.10/nnnn flags ACK on interface vpn
146-1100011No route to 10.10.10.3 from 192.168.1.45
156-1990021PIX startup completed. Beginning operation.
166-30201377Built outbound TCP connection nnnnn for outside:12.129.129.149/1521 (12.129.129.149/1521) to inside:172.18.10.99/nnnn (216.13.68.100/nnnn)
176-30201474Teardown TCP connection nnnnn for outside:12.129.129.149/1521 to inside:172.18.10.99/nnnn duration 0:00:01 bytes 428 TCP FINs
186-302015151Built inbound UDP connection 132900 for vpn:10.42.0.141/nnnn (10.42.0.141/nnnn) to inside:172.18.10.10/514 (172.18.10.10/514)
196-302016206Teardown UDP connection 132740 for outside:64.12.66.9/50 to inside:172.18.10.99/53 duration 0:02:01 bytes 50
206-3050111Built dynamic ICMP translation from inside:172.18.10.67/nnnn to outside:216.13.68.99/279
216-3050122Teardown dynamic ICMP translation from inside:172.18.10.67/443 to outside:216.13.68.99/280 duration 0:00:31
226-3070031telnet login session failed from 192.168.1.4 (3 attempts) on interface inside
236-6050021HTTP daemon connection limit exceeded
247-7010011alloc_user() out of Tcp_user objects
257-7090021FO unreplicable: cmd=show config


Details for the 172.17.250.4 firewall.

Severity level 1 (Alert) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:03:4101/24/03 00:03:411-101002(Primary) Bad failover cable.1
201/24/03 00:03:4101/24/03 00:03:411-105001(Primary) Disabling failover.1
301/24/03 00:03:4101/24/03 00:03:411-106022Deny protocol connection spoof from 203.45.122.5 to 216.208.34.22 on interface inside1

Severity level 2 (Critical) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:03:4101/24/03 00:03:412-110003No interface is configured (with name out_vpn).1
201/24/03 00:03:2401/24/03 00:03:242-709007Configuration replication failed for command write memory1

Severity level 3 (Error) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:00:5401/24/03 00:00:553-106011Deny inbound (No xlate) tcp src outside:80.142.137.204/nnnn dst outside:216.13.68.122/213
201/24/03 00:00:5401/24/03 00:00:553-106011Deny inbound (No xlate) tcp src outside:80.142.137.204/nnnn dst outside:216.13.68.99/213
301/24/03 00:03:4101/24/03 00:03:413-211003CPU utilization for time seconds = %751
401/24/03 00:03:4101/24/03 00:03:413-202001Out of address translation slots!1

Severity level 4 (Warning) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:00:5401/24/03 00:01:074-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.115/21 by access-group "acl_out"4
201/24/03 00:00:5401/24/03 00:01:074-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.119/21 by access-group "acl_out"4
301/24/03 00:00:5401/24/03 00:01:034-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.125/21 by access-group "acl_out"3
401/24/03 00:00:5401/24/03 00:01:034-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.104/21 by access-group "acl_out"3
501/24/03 00:00:5401/24/03 00:01:034-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.113/21 by access-group "acl_out"3
601/24/03 00:00:5401/24/03 00:01:034-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.102/21 by access-group "acl_out"3
701/24/03 00:00:5401/24/03 00:01:034-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.105/21 by access-group "acl_out"3
801/24/03 00:00:5401/24/03 00:01:034-106023Deny tcp src outside:80.142.137.204/nnnn dst inside:216.13.68.109/21 by access-group "acl_out"3
901/24/03 00:03:3001/24/03 00:03:304-309004Manager session limit exceeded. Connection request from 192.168.1.5 on interface inside1

Severity level 5 (Notification) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:00:4201/24/03 00:00:425-199001PIX reload command executed from telnet (192.168.1.4).1
201/24/03 00:03:4101/24/03 00:03:415-111006Console Login from user at 192.168.1.41

Severity level 6 (Informational) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:00:1501/24/03 00:03:326-302013Built outbound TCP connection nnnnn for outside:63.251.224.177/1521 (63.251.224.177/1521) to inside:172.18.10.99/nnnn (216.13.68.100/nnnn)14
201/24/03 00:00:0001/24/03 00:03:326-302014Teardown TCP connection nnnnn for outside:63.251.224.177/1521 to inside:172.18.10.99/nnnn duration 0:00:01 bytes 86 TCP FINs13
301/24/03 00:00:2101/24/03 00:00:346-106015Deny TCP (no connection) from 172.18.11.200/nnnn to 172.18.10.47/1521 flags ACK on interface vpn7
401/24/03 00:01:1601/24/03 00:02:166-302014Teardown TCP connection nnnnn for outside:65.244.21.149/1521 to inside:172.18.10.99/nnnn duration 0:00:01 bytes 427 TCP FINs5
501/24/03 00:01:1501/24/03 00:02:166-302013Built outbound TCP connection nnnnn for outside:65.244.21.149/1521 (65.244.21.149/1521) to inside:172.18.10.99/nnnn (216.13.68.100/nnnn)5
601/24/03 00:02:4101/24/03 00:02:426-302013Built inbound TCP connection nnnnn for vpn:10.42.0.143/nnnn (10.42.0.143/nnnn) to inside:172.18.10.11/139 (172.18.10.11/139)4
701/24/03 00:02:3001/24/03 00:02:316-302014Teardown TCP connection nnnnn for vpn:10.42.0.144/nnnn to inside:172.18.10.11/139 duration 0:00:01 bytes 741 TCP FINs4
801/24/03 00:02:4101/24/03 00:02:426-302014Teardown TCP connection nnnnn for vpn:10.42.0.143/nnnn to inside:172.18.10.11/139 duration 0:00:01 bytes 741 TCP FINs4
901/24/03 00:02:3001/24/03 00:02:316-302013Built inbound TCP connection nnnnn for vpn:10.42.0.144/nnnn (10.42.0.144/nnnn) to inside:172.18.10.11/139 (172.18.10.11/139)4
1001/24/03 00:01:2201/24/03 00:01:236-302013Built inbound TCP connection nnnnn for vpn:10.42.0.173/nnnn (10.42.0.173/nnnn) to inside:172.18.10.67/1984 (172.18.10.67/1984)3
1101/24/03 00:02:4101/24/03 00:02:416-302013Built inbound TCP connection nnnnn for vpn:10.42.0.143/nnnn (10.42.0.143/nnnn) to inside:172.18.10.78/139 (172.18.10.78/139)2
1201/24/03 00:01:1501/24/03 00:01:156-302013Built inbound TCP connection nnnnn for vpn:172.17.102.25/nnnn (172.17.102.25/nnnn) to inside:172.18.10.67/1984 (172.18.10.67/1984)2
1301/24/03 00:00:1301/24/03 00:03:166-302014Teardown TCP connection nnnnn for vpn:192.168.150.33/80 to inside:172.18.10.39/nnnn duration 0:00:01 bytes 205 TCP FINs2
1401/24/03 00:00:1201/24/03 00:03:156-302013Built outbound TCP connection nnnnn for vpn:10.42.0.164/2049 (10.42.0.164/2049) to inside:172.18.10.39/nnnn (172.18.10.39/nnnn)2
1501/24/03 00:00:1001/24/03 00:03:136-302013Built outbound TCP connection nnnnn for outside:209.47.182.19/80 (209.47.182.19/80) to inside:172.18.10.39/nnnn (216.13.68.113/nnnn)2
1601/24/03 00:00:1301/24/03 00:03:166-302013Built outbound TCP connection nnnnn for vpn:192.168.150.33/80 (192.168.150.33/80) to inside:172.18.10.39/nnnn (172.18.10.39/nnnn)2
1701/24/03 00:03:3001/24/03 00:03:316-302013Built inbound TCP connection nnnnn for vpn:10.42.0.181/nnnn (10.42.0.181/nnnn) to inside:172.18.10.67/1984 (172.18.10.67/1984)2
1801/24/03 00:00:1701/24/03 00:03:206-302014Teardown TCP connection nnnnn for vpn:172.17.102.24/80 to inside:172.18.10.39/nnnn duration 0:00:01 bytes 339 TCP FINs2
1901/24/03 00:00:1101/24/03 00:03:146-302014Teardown TCP connection nnnnn for outside:209.47.182.19/80 to inside:172.18.10.39/nnnn duration 0:00:01 bytes 206 TCP FINs2
2001/24/03 00:00:1701/24/03 00:03:206-302014Teardown TCP connection nnnnn for vpn:172.17.102.23/80 to inside:172.18.10.39/nnnn duration 0:00:01 bytes 339 TCP FINs2
2101/24/03 00:02:5101/24/03 00:02:516-302013Built inbound TCP connection nnnnn for vpn:192.168.0.218/nnnn (192.168.0.218/nnnn) to inside:172.18.10.67/1984 (172.18.10.67/1984)2
2201/24/03 00:03:2701/24/03 00:03:286-302013Built inbound TCP connection nnnnn for vpn:192.168.0.20/nnnn (192.168.0.20/nnnn) to inside:172.18.10.67/1984 (172.18.10.67/1984)2
2301/24/03 00:03:1701/24/03 00:03:326-302013Built outbound TCP connection nnnnn for outside:12.129.129.149/1521 (12.129.129.149/1521) to inside:172.18.10.99/nnnn (216.13.68.100/nnnn)2
2401/24/03 00:02:5101/24/03 00:02:526-302013Built inbound TCP connection nnnnn for vpn:192.168.0.21/nnnn (192.168.0.21/nnnn) to inside:172.18.10.67/1984 (172.18.10.67/1984)2
2501/24/03 00:00:2101/24/03 00:00:216-106015Deny TCP (no connection) from 172.18.11.200/nnnn to 172.18.10.47/1521 flags PSH ACK on interface vpn2
2601/24/03 00:00:1301/24/03 00:03:156-302014Teardown TCP connection nnnnn for vpn:10.42.0.164/2049 to inside:172.18.10.39/nnnn duration 0:00:00 bytes 0 TCP FINs2
2701/24/03 00:00:1101/24/03 00:03:146-302013Built outbound TCP connection nnnnn for vpn:10.42.0.164/22 (10.42.0.164/22) to inside:172.18.10.39/nnnn (172.18.10.39/nnnn)2
2801/24/03 00:02:4101/24/03 00:02:416-302014Teardown TCP connection nnnnn for vpn:10.42.0.143/nnnn to inside:172.18.10.78/139 duration 0:00:01 bytes 766 TCP FINs2
2901/24/03 00:00:1601/24/03 00:03:196-302013Built outbound TCP connection nnnnn for vpn:172.17.102.24/80 (172.17.102.24/80) to inside:172.18.10.39/nnnn (172.18.10.39/nnnn)2
3001/24/03 00:00:1601/24/03 00:03:196-302013Built outbound TCP connection nnnnn for vpn:172.17.102.23/80 (172.17.102.23/80) to inside:172.18.10.39/nnnn (172.18.10.39/nnnn)2
3101/24/03 00:03:1701/24/03 00:03:326-302014Teardown TCP connection nnnnn for outside:12.129.129.149/1521 to inside:172.18.10.99/nnnn duration 0:00:01 bytes 428 TCP FINs2
3201/24/03 00:00:1101/24/03 00:03:146-302013Built outbound TCP connection nnnnn for vpn:10.42.0.167/22 (10.42.0.167/22) to inside:172.18.10.39/nnnn (172.18.10.39/nnnn)2
3301/24/03 00:02:0301/24/03 00:02:036-302016Teardown UDP connection 132661 for outside:152.163.140.10/52 to inside:172.18.10.99/53 duration 0:02:01 bytes 391
3401/24/03 00:00:4401/24/03 00:00:446-302016Teardown UDP connection 132446 for vpn:10.42.0.141/nnnn to inside:172.18.10.10/514 duration 0:02:01 bytes 2771
3501/24/03 00:02:4901/24/03 00:02:496-302015Built inbound UDP connection 132806 for vpn:10.42.0.141/nnnn (10.42.0.141/nnnn) to inside:172.18.10.10/514 (172.18.10.10/514)1
3601/24/03 00:00:3301/24/03 00:00:336-302016Teardown UDP connection 132388 for outside:64.12.66.8/51 to inside:172.18.10.99/53 duration 0:02:01 bytes 501
3701/24/03 00:02:4601/24/03 00:02:466-302015Built outbound UDP connection 132796 for vpn:10.42.0.141/138 (10.42.0.141/138) to inside:172.18.10.10/138 (172.18.10.10/138)1
3801/24/03 00:00:4401/24/03 00:00:446-302016Teardown UDP connection 132419 for vpn:10.42.0.141/nnnn to inside:172.18.10.10/514 duration 0:02:01 bytes 2891
3901/24/03 00:00:4401/24/03 00:00:446-302016Teardown UDP connection 132458 for vpn:10.42.0.141/nnnn to inside:172.18.10.10/514 duration 0:02:01 bytes 2771
4001/24/03 00:03:2101/24/03 00:03:216-302015Built inbound UDP connection 132846 for vpn:172.18.11.194/137 (172.18.11.194/137) to inside:172.18.10.10/137 (172.18.10.10/137)1
4101/24/03 00:00:4401/24/03 00:00:446-302016Teardown UDP connection 132413 for vpn:10.42.0.141/1541 to inside:172.18.10.10/514 duration 0:02:01 bytes 2911
4201/24/03 00:00:4401/24/03 00:00:446-302016Teardown UDP connection 132421 for vpn:10.42.0.141/nnnn to inside:172.18.10.10/514 duration 0:02:01 bytes 1701
4301/24/03 00:01:3101/24/03 00:01:316-302015Built outbound UDP connection 132734 for outside:205.151.222.254/53 (205.151.222.254/53) to inside:172.18.10.10/nnnn (216.13.68.111/nnnn)1
4401/24/03 00:03:0001/24/03 00:03:006-302015Built inbound UDP connection 132826 for outside:152.163.140.10/nnnn (152.163.140.10/nnnn) to inside:172.18.10.99/53 (216.13.68.100/53)1
4501/24/03 00:03:4101/24/03 00:03:416-302015Built inbound UDP connection 132900 for vpn:10.42.0.141/nnnn (10.42.0.141/nnnn) to inside:172.18.10.10/514 (172.18.10.10/514)1
4601/24/03 00:01:5901/24/03 00:01:596-302016Teardown UDP connection 132658 for outside:205.188.152.8/50 to inside:172.18.10.99/53 duration 0:02:01 bytes 501
4701/24/03 00:00:0501/24/03 00:00:056-302016Teardown UDP connection 132374 for outside:64.108.53.158/nnnn to inside:172.18.10.99/53 duration 0:02:01 bytes 391
4801/24/03 00:01:1601/24/03 00:01:166-302013Built inbound TCP connection nnnnn for vpn:192.168.0.20/1600 (192.168.0.20/1600) to inside:172.18.10.10/139 (172.18.10.10/139)1
4901/24/03 00:02:4901/24/03 00:02:496-302015Built inbound UDP connection 132807 for vpn:10.42.0.141/nnnn (10.42.0.141/nnnn) to inside:172.18.10.10/514 (172.18.10.10/514)1
5001/24/03 00:00:5401/24/03 00:00:546-302015Built inbound UDP connection 132687 for vpn:192.168.0.159/138 (192.168.0.159/138) to inside:172.18.10.10/138 (172.18.10.10/138)1
There were 407 more messages to be reported but the listing is limited to 50!!!

Severity level 7 (Debugging) details for the 172.17.250.4 firewall. Back to top
NoFirst MessageLast MessageCodeMessageCount
101/24/03 00:03:4101/24/03 00:03:417-709002FO unreplicable: cmd=show config1
201/24/03 00:03:3801/24/03 00:03:387-701001alloc_user() out of Tcp_user objects1

Top 50 protocols used for the 172.17.250.4 firewall. Back to top
NoProtocolConnections% 
153 - dns65 28.5                              
2514 - syslog50 21.92                       
31521 - oracle23 10.08            
4139 - netbios15 6.57        
51984 - big brother14 6.14        
6138 - netbios12 5.26       
780 - http11 4.82      
8161 - snmp7 3.07     
922 - ssh7 3.07     
1025 - smtp4 1.75   
11137 - netbios4 1.75   
122049 - nfs2 0.87  
13162 - snmp-trap1 0.43  
14267071 0.43  
15446901 0.43  
16448111 0.43  
17596571 0.43  
18447871 0.43  
19367761 0.43  
2025291 0.43  
21447501 0.43  
22364301 0.43  
23633581 0.43  
2442 - ms wins1 0.43  
25606601 0.43  
26446301 0.43  

Top 50 Destinations for the 172.17.250.4 firewall. Back to top
NoDestinationConnectionsProtocols
163.251.224.17714 TCP/1521 - oracle
265.244.21.1495 TCP/1521 - oracle
3205.151.222.2544 UDP/53 - dns
4192.168.0.2184 TCP/42 - ms wins,UDP/138 - netbios,UDP/161 - snmp,UDP/44787
510.42.0.1644 TCP/2049 - nfs,TCP/22 - ssh
610.42.0.1413 TCP/25 - smtp,UDP/138 - netbios
710.42.0.1622 TCP/1521 - oracle,TCP/22 - ssh
812.129.129.1492 TCP/1521 - oracle
9192.175.48.422 UDP/53 - dns
1010.42.0.1672 TCP/22 - ssh
11172.17.102.232 TCP/80 - http
12172.17.102.242 TCP/80 - http
13192.168.150.332 TCP/80 - http
14209.47.182.192 TCP/80 - http
1510.42.0.1562 TCP/1521 - oracle,TCP/22 - ssh
16129.33.164.842 UDP/53 - dns
17192.168.0.201 TCP/139 - netbios
18192.168.0.211 UDP/138 - netbios
1910.10.35.1801 UDP/161 - snmp
20209.47.182.21 TCP/25 - smtp
21172.17.102.101 TCP/80 - http
2210.10.15.21 UDP/161 - snmp
2310.10.35.1201 UDP/161 - snmp
2410.10.35.21 UDP/161 - snmp
2510.42.0.1421 TCP/25 - smtp
26209.47.182.121 TCP/80 - http
2710.42.0.1711 TCP/139 - netbios
2810.42.0.1291 UDP/161 - snmp
29207.68.162.2531 TCP/80 - http
30172.18.11.31 UDP/161 - snmp
31192.168.0.121 UDP/138 - netbios
32192.43.172.301 UDP/53 - dns
3310.42.0.1651 TCP/22 - ssh

Top 50 internal source IPs for the 172.17.250.4 firewall. Back to top
NoSourceConnectionsProtocolsTraffic (kb)
1172.18.10.3932 TCP/1521,TCP/2049,TCP/22,TCP/25,TCP/80,UDP/161,UDP/4478724
2172.18.10.9921 TCP/15217