|
|||||||||||
|
RE: help with log entries
From: David Gillett <gillettdavid(at)fhda.edu>
Date: Thu Feb 27 2003 - 14:25:44 EST
The PIX is a "stateful inspection" firewall, which means that it checks that incoming packets are part of an established connection. The "(no connection)" indicates that this check has failed for the packet. So what I expect you're seeing is that an internal client has been downloading mail from -- or port-scanning looking for a POP3 exploit -- 161.58.238.151 and 200.24.76.3 and 200.24.76.8, and has abandoned the connections (perhaps the exploit failed or their password was wrong). For some reason, the PIX has seen them drop the connection, or (more likely) has timed it out. Finally the server has timed it out, and it's the server "hanging up the phone" that the PIX is seeing and logging. The packets from 66.35.250.206 are something else. I've seen a client use RST to hang up on a server, but never three times as seen here. David Gillett > -----Original Message-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:51 EDT |
||||||||||
|
|||||||||||