Altair Technologies - - "SEF8" log profile analysis for the period
Tue Aug 16 00:00:00 2005 to Tue Aug 16 23:59:59 2005

-
Research links: - Go to top
-
Summary: - Go to top

Firewall First Event Last Event
bastion_sef8.altairtech.ca 08/16/05 21:50:30 08/16/05 23:59:59

-
Analyzed logs: - Go to top

Log file Log size (kb) Log entries
C:\Docs\Projects\FGNG\FGNGSEF8\logs\logfile.txt.20050816-1029,153.1867,544

-
Statistics for the bastion_sef8.altairtech.ca firewall: - Go to top

-
No Host IP Host Name Protocols Sent Received Total % Comment
192.168.5.49   ICMP/8 - ping, TCP/80 - http  124.78  149,389.84  149,514.61  77.95   
192.168.1.24   TCP/80 - http  176.04  22,528.02  22,704.06  11.84   
192.168.101.20   TCP/25 - smtp, UDP/123 - ntp, ICMP/3 - unreach, TCP/80 - http  11.62  7,585.67  7,597.29  3.96   
192.168.1.13   TCP/80 - http  582.80  2,424.15  3,006.96  1.57   
192.168.4.75   TCP/80 - http  832.73  954.58  1,787.31  0.93   
192.168.127.21   TCP/80 - http  156.49  455.46  611.95  0.32   
192.168.4.168   TCP/80 - http  204.33  330.20  534.53  0.28   
192.168.1.109   UDP/137 - netbios, TCP/80 - http  29.91  499.36  529.27  0.28   
192.168.5.109   TCP/80 - http  31.90  414.10  446.00  0.23   
10  192.168.4.93   TCP/80 - http  42.40  380.26  422.66  0.22   
11  192.168.2.14   UDP/2967 - symantec-av, TCP/3389 - ms rdp, ICMP/3 - unreach  36.38  383.21  419.59  0.22   
12  192.168.4.110   TCP/25 - smtp, TCP/80 - http  58.68  345.61  404.29  0.21   
13  192.168.127.119   TCP/80 - http  65.33  297.31  362.65  0.19   
14  192.168.5.165   TCP/80 - http  15.39  301.87  317.26  0.17   
15  192.168.254.11   TCP/110 - pop3, TCP/80 - http  126.62  145.34  271.96  0.14   
16  192.168.6.31   TCP/80 - http  48.08  209.85  257.93  0.13   
17  192.168.117.148   TCP/80 - http  7.84  189.66  197.49  0.10   
18  192.168.5.124   TCP/80 - http  2.93  158.22  161.15  0.08   
19  192.168.4.43   TCP/80 - http  7.66  127.42  135.08  0.07   
20  192.168.5.66   UDP/123 - ntp, ICMP/3 - unreach, TCP/80 - http  46.82  80.41  127.23  0.07   
21  192.168.117.56   TCP/70, TCP/80 - http  32.87  73.71  106.58  0.06   
22  192.168.3.246   TCP/25 - smtp  85.92  18.22  104.14  0.05   
23  192.168.254.12   TCP/80 - http  26.71  75.33  102.04  0.05   
24  192.168.4.182   TCP/80 - http  30.27  60.10  90.37  0.05   
25  192.168.5.15   TCP/80 - http  33.17  54.51  87.68  0.05   
26  192.168.4.57   TCP/80 - http  8.38  60.10  68.47  0.04   
27  192.168.4.97   TCP/80 - http  3.47  64.16  67.63  0.04   
28  192.168.118.17   UDP/161 - snmp, ICMP/3 - unreach, TCP/80 - http, TCP/161  3.73  60.59  64.33  0.03   
29  192.168.254.10   TCP/80 - http  26.29  37.25  63.54  0.03   
30  192.168.4.41   TCP/80 - http  18.01  37.00  55.01  0.03   
31  192.168.4.30   TCP/80 - http  2.35  36.72  39.07  0.02   
32  192.168.4.222   TCP/80 - http  2.05  36.17  38.22  0.02   
33  192.168.127.65   TCP/80 - http  2.05  36.16  38.22  0.02   
34  192.168.4.211   TCP/80 - http  2.05  36.16  38.22  0.02   
35  192.168.117.1   TCP/80 - http  2.05  36.16  38.22  0.02   
36  192.168.117.54   TCP/80 - http  2.05  35.49  37.54  0.02   
37  192.168.6.95   TCP/80 - http  2.05  35.49  37.54  0.02   
38  192.168.3.114   TCP/80 - http  2.05  35.49  37.54  0.02   
39  192.168.6.83   TCP/80 - http  2.05  35.48  37.54  0.02   
40  192.168.117.15   TCP/80 - http  2.05  35.48  37.54  0.02   
41  192.168.4.44   TCP/80 - http  16.18  20.87  37.04  0.02   
42  192.168.6.64   TCP/80 - http  2.05  34.80  36.86  0.02   
43  192.168.117.119   TCP/80 - http  2.05  34.80  36.86  0.02   
44  192.168.117.159   TCP/80 - http  2.05  34.80  36.86  0.02   
45  192.168.117.117   TCP/80 - http  2.05  34.80  36.86  0.02   
46  192.168.6.49   TCP/80 - http  2.05  34.80  36.86  0.02   
47  192.168.10.165   TCP/80 - http  2.05  34.80  36.86  0.02   
48  192.168.117.209   TCP/80 - http  2.05  34.80  36.86  0.02   
49  192.168.3.95   TCP/80 - http  2.05  34.80  36.86  0.02   
50  192.168.6.91   TCP/80 - http  2.05  34.80  36.86  0.02   
  Total     2,935.10  188,469.25  191,404.36     
There were more records in this section but the reporting is limited to 50

-
No Host IP Host Name Protocols Sent Received Total % Comment
169.166.17.140eccb01-00-barwga-69-166-17-140.atlaga.adelphia.netTCP/80 - http75.9122,506.1122,582.02 16.96 
224.98.85.128c-24-98-85-128.hsd1.ga.comcast.netTCP/80 - http440.758,848.959,289.70 6.98 
368.219.44.6adsl-219-44-6.asm.bellsouth.netTCP/80 - http327.027,490.507,817.53 5.87 
468.214.28.212adsl-214-28-212.asm.bellsouth.netTCP/80 - http565.275,768.376,333.64 4.76 
569.160.226.232ga-gwinnett-cuda1-c3b-232.atlaga.adelphia.netTCP/80 - http30.465,299.955,330.41 4.00 
624.30.65.101c-24-30-65-101.hsd1.ga.comcast.netTCP/80 - http151.704,993.185,144.88 3.86 
7205.152.59.73imf25aec.mail.bellsouth.netTCP/25 - smtp3,944.381.093,945.47 2.96 
868.211.104.206adsl-211-104-206.asm.bellsouth.netTCP/80 - http148.563,165.523,314.08 2.49 
969.166.17.147eccb01-00-barwga-69-166-17-147.atlaga.adelphia.netTCP/80 - http83.442,635.922,719.36 2.04 
1065.13.4.211adsl-065-013-004-211.sip.asm.bellsouth.netTCP/80 - http199.002,392.992,591.99 1.95 
1172.10.67.181181-67-10-72.pineland.netTCP/80 - http109.242,220.032,329.27 1.75 
1267.140.207.85h85.207.140.67.ip.alltel.netTCP/80 - http255.052,063.732,318.78 1.74 
1366.32.178.160user-1121cl0.dsl.mindspring.comTCP/80 - http43.622,237.262,280.87 1.71 
1468.190.45.14168-190-45-141.dhcp.athn.ga.charter.comTCP/80 - http257.171,919.072,176.25 1.63 
1567.140.197.146h146.197.140.67.ip.alltel.netTCP/80 - http188.611,599.921,788.53 1.34 
1668.158.180.14adsl-158-180-14.mia.bellsouth.netTCP/80 - http164.891,610.391,775.29 1.33 
1724.98.80.98c-24-98-80-98.hsd1.ga.comcast.netTCP/80 - http65.131,610.491,675.62 1.26 
1868.154.96.113adsl-154-96-113.asm.bellsouth.netTCP/80 - http38.981,593.251,632.23 1.23 
19166.102.165.166ispmxmta05-srv.alltel.netTCP/25 - smtp1,618.671.921,620.60 1.22 
2068.155.166.147adsl-155-166-147.asm.bellsouth.netTCP/80 - http77.321,486.691,564.01 1.17 
2167.140.205.233h233.205.140.67.ip.alltel.netTCP/80 - http105.021,391.561,496.58 1.12 
22162.39.213.149h149.213.39.162.ip.alltel.netTCP/80 - http124.441,121.011,245.46 0.94 
23166.102.165.170ispmxmta09-srv.alltel.netTCP/25 - smtp1,175.043.841,178.88 0.89 
2466.249.66.178crawl-66-249-66-178.googlebot.comTCP/80 - http23.791,144.631,168.41 0.88 
25207.46.98.83msnbot.msn.comTCP/80 - http37.591,093.711,131.30 0.85 
26207.69.140.24ca01-ch03-bl06.accel.atl.earthlink.netTCP/80 - http83.341,021.041,104.38 0.83 
2764.12.137.7imo-m26.mx.aol.comTCP/25 - smtp1,053.880.531,054.41 0.79 
28166.102.165.167ispmxmta06-srv.alltel.netTCP/25 - smtp1,048.095.531,053.62 0.79 
29151.193.165.154p259.travelocity.comTCP/25 - smtp1,048.862.151,051.01 0.79 
3067.140.202.179h179.202.140.67.ip.alltel.netTCP/80 - http118.36827.34945.70 0.71 
3168.158.52.86adsl-158-52-86.asm.bellsouth.netTCP/80 - http15.74906.68922.41 0.69 
32172.163.186.148ACA3BA94.ipt.aol.comTCP/80 - http52.12772.23824.36 0.62 
33206.190.49.119web54309.mail.yahoo.comTCP/25 - smtp725.110.44725.55 0.54 
34206.190.38.23web50008.mail.yahoo.comTCP/25 - smtp714.110.44714.55 0.54 
3568.233.186.35eccb01-00-barwga-68-233-186-35.atlaga.adelphia.netTCP/80 - http21.91625.44647.35 0.49 
36151.193.165.14p136.travelocity.comTCP/25 - smtp578.602.14580.74 0.44 
3764.12.116.67cache-mtc-ab03.proxy.aol.comTCP/80 - http9.62554.52564.14 0.42 
38151.193.165.236mail8.travelocity.comTCP/25 - smtp550.601.62552.22 0.41 
39158.93.6.9stjames1.mcg.eduTCP/25 - smtp501.160.44501.59 0.38 
40152.163.100.5cache-rtc-aa01.proxy.aol.comTCP/80 - http8.87468.85477.72 0.36 
4164.12.117.6cache-mtc-ae02.proxy.aol.comTCP/80 - http8.86449.99458.85 0.34 
4264.12.116.131cache-mtc-ac02.proxy.aol.comTCP/80 - http10.24441.10451.35 0.34 
4368.117.216.13368-117-216-133.dhcp.athn.ga.charter.comTCP/80 - http2.18440.97443.15 0.33 
4464.12.116.130cache-mtc-ac01.proxy.aol.comTCP/80 - http14.76426.51441.27 0.33 
4568.142.251.45lj2435.inktomisearch.comTCP/80 - http0.43438.39438.82 0.33 
4666.147.139.22info02.snapshotdesign.comTCP/25 - smtp403.7122.91426.62 0.32 
4764.136.20.164outbound-mail.nyc.untd.comTCP/25 - smtp420.460.79421.26 0.32 
4864.233.162.196zproxy.gmail.comTCP/25 - smtp399.710.47400.18 0.30 
49205.188.144.207imo-d21.mx.aol.comTCP/25 - smtp398.081.84399.93 0.30 
50170.140.8.221pales.cc.emory.eduTCP/25 - smtp397.750.53398.28 0.30 
 Total  18,847.0291,989.53110,836.56 
There were more records in this section but the reporting is limited to 50

-
No Host IP Host Name Protocols Total % Comment
192.168.101.20   TCP/25 - smtp, ICMP/3 - unreach, UDP/123 - ntp, TCP/80 - http  858.74  100.00   
   Total      858.74       
-
No Protocol Sent Received Total % Comment
TCP/80 - http  8,132.35  294,639.69  302,772.05  93.17   
TCP/25 - smtp  21,297.03  441.26  21,738.29  6.69   
TCP/3389 - ms rdp  36.38  383.21  419.59  0.13   
TCP/70  0.21  22.45  22.66  0.01   
TCP/110 - pop3  5.15  11.79  16.93  0.01   
ICMP/8 - ping  1.98  0.00  1.98  0.00   
TCP/33443  0.00  0.00  0.00   
TCP/33444  0.00  0.00  0.00   
TCP/139 - netbios  0.00  0.00  0.00   
10  TCP/33445  0.00  0.00  0.00   
11  TCP/33446  0.00  0.00  0.00   
12  TCP/33447  0.00  0.00  0.00   
13  TCP/33448  0.00  0.00  0.00   
14  TCP/443 - ssl-https  0.00  0.00  0.00   
15  TCP/33449  0.00  0.00  0.00   
16  TCP/445 - netbios  0.00  0.00  0.00   
17  UDP/38293  0.00  0.00  0.00   
18  UDP/2967 - symantec-av  0.00  0.00  0.00   
19  UDP/137 - netbios  0.00  0.00  0.00   
20  UDP/138 - netbios  0.00  0.00  0.00   
21  UDP/33440  0.00  0.00  0.00   
22  UDP/33441  0.00  0.00  0.00   
23  TCP/1026 - trojan  0.00  0.00  0.00   
24  TCP/1027 - icq  0.00  0.00  0.00   
25  TCP/161  0.00  0.00  0.00   
  Total  0.00  0.00  0.00   
There were more records in this section but the reporting is limited to 25

-
No First Last Source IP Source Host Destination IP Destination Host Sent Received Total Count Comment
08/16/05 22:23:16  08/16/05 23:28:26