Altair Technologies - - "SEF8" log profile analysis for the period
Tue Aug 16 00:00:00 2005 to Tue Aug 16 23:59:59 2005
| TCP/IP Protocol |
| Whois |
| Send your comments or suggestions to the FireGen developers! |
| Glossary |
| Analysis performance |
| Firewall | First Event | Last Event |
| bastion_sef8.altairtech.ca | 08/16/05 21:50:30 | 08/16/05 23:59:59 |
| Log file | Log size (kb) | Log entries |
| C:\Docs\Projects\FGNG\FGNGSEF8\logs\logfile.txt.20050816-10 | 29,153.18 | 67,544 |
| Sections | Sub-sections |
| Traffic | From internal hosts From external hosts Towards hosts behind the firewall By hour |
| Protocols | Top 25 HTTP-HTTPS FTP SMTP Email clients Other protocols |
| URLs | Top 50 |
| Denials | Protocols - 42 By hour Sources - 135 Destinations - 2,763 Connections - 8,345 |
| Warnings | 239 |
| Notifications | 53 |
| VPNs | 0 |
| Management | 0 |
| Daemons | 14 |
| Message types | 19 |
| No | Host IP | Host Name | Protocols | Sent | Received | Total | % | Comment | ||||||
| 1 | 192.168.5.49 |   | ICMP/8 - ping, TCP/80 - http | 124.78 | 149,389.84 | 149,514.61 | 77.95 | |||||||
| 2 | 192.168.1.24 |   | TCP/80 - http | 176.04 | 22,528.02 | 22,704.06 | 11.84 | |||||||
| 3 | 192.168.101.20 |   | TCP/25 - smtp, UDP/123 - ntp, ICMP/3 - unreach, TCP/80 - http | 11.62 | 7,585.67 | 7,597.29 | 3.96 | |||||||
| 4 | 192.168.1.13 |   | TCP/80 - http | 582.80 | 2,424.15 | 3,006.96 | 1.57 | |||||||
| 5 | 192.168.4.75 |   | TCP/80 - http | 832.73 | 954.58 | 1,787.31 | 0.93 | |||||||
| 6 | 192.168.127.21 |   | TCP/80 - http | 156.49 | 455.46 | 611.95 | 0.32 | |||||||
| 7 | 192.168.4.168 |   | TCP/80 - http | 204.33 | 330.20 | 534.53 | 0.28 | |||||||
| 8 | 192.168.1.109 |   | UDP/137 - netbios, TCP/80 - http | 29.91 | 499.36 | 529.27 | 0.28 | |||||||
| 9 | 192.168.5.109 |   | TCP/80 - http | 31.90 | 414.10 | 446.00 | 0.23 | |||||||
| 10 | 192.168.4.93 |   | TCP/80 - http | 42.40 | 380.26 | 422.66 | 0.22 | |||||||
| 11 | 192.168.2.14 |   | UDP/2967 - symantec-av, TCP/3389 - ms rdp, ICMP/3 - unreach | 36.38 | 383.21 | 419.59 | 0.22 | |||||||
| 12 | 192.168.4.110 |   | TCP/25 - smtp, TCP/80 - http | 58.68 | 345.61 | 404.29 | 0.21 | |||||||
| 13 | 192.168.127.119 |   | TCP/80 - http | 65.33 | 297.31 | 362.65 | 0.19 | |||||||
| 14 | 192.168.5.165 |   | TCP/80 - http | 15.39 | 301.87 | 317.26 | 0.17 | |||||||
| 15 | 192.168.254.11 |   | TCP/110 - pop3, TCP/80 - http | 126.62 | 145.34 | 271.96 | 0.14 | |||||||
| 16 | 192.168.6.31 |   | TCP/80 - http | 48.08 | 209.85 | 257.93 | 0.13 | |||||||
| 17 | 192.168.117.148 |   | TCP/80 - http | 7.84 | 189.66 | 197.49 | 0.10 | |||||||
| 18 | 192.168.5.124 |   | TCP/80 - http | 2.93 | 158.22 | 161.15 | 0.08 | |||||||
| 19 | 192.168.4.43 |   | TCP/80 - http | 7.66 | 127.42 | 135.08 | 0.07 | |||||||
| 20 | 192.168.5.66 |   | UDP/123 - ntp, ICMP/3 - unreach, TCP/80 - http | 46.82 | 80.41 | 127.23 | 0.07 | |||||||
| 21 | 192.168.117.56 |   | TCP/70, TCP/80 - http | 32.87 | 73.71 | 106.58 | 0.06 | |||||||
| 22 | 192.168.3.246 |   | TCP/25 - smtp | 85.92 | 18.22 | 104.14 | 0.05 | |||||||
| 23 | 192.168.254.12 |   | TCP/80 - http | 26.71 | 75.33 | 102.04 | 0.05 | |||||||
| 24 | 192.168.4.182 |   | TCP/80 - http | 30.27 | 60.10 | 90.37 | 0.05 | |||||||
| 25 | 192.168.5.15 |   | TCP/80 - http | 33.17 | 54.51 | 87.68 | 0.05 | |||||||
| 26 | 192.168.4.57 |   | TCP/80 - http | 8.38 | 60.10 | 68.47 | 0.04 | |||||||
| 27 | 192.168.4.97 |   | TCP/80 - http | 3.47 | 64.16 | 67.63 | 0.04 | |||||||
| 28 | 192.168.118.17 |   | UDP/161 - snmp, ICMP/3 - unreach, TCP/80 - http, TCP/161 | 3.73 | 60.59 | 64.33 | 0.03 | |||||||
| 29 | 192.168.254.10 |   | TCP/80 - http | 26.29 | 37.25 | 63.54 | 0.03 | |||||||
| 30 | 192.168.4.41 |   | TCP/80 - http | 18.01 | 37.00 | 55.01 | 0.03 | |||||||
| 31 | 192.168.4.30 |   | TCP/80 - http | 2.35 | 36.72 | 39.07 | 0.02 | |||||||
| 32 | 192.168.4.222 |   | TCP/80 - http | 2.05 | 36.17 | 38.22 | 0.02 | |||||||
| 33 | 192.168.127.65 |   | TCP/80 - http | 2.05 | 36.16 | 38.22 | 0.02 | |||||||
| 34 | 192.168.4.211 |   | TCP/80 - http | 2.05 | 36.16 | 38.22 | 0.02 | |||||||
| 35 | 192.168.117.1 |   | TCP/80 - http | 2.05 | 36.16 | 38.22 | 0.02 | |||||||
| 36 | 192.168.117.54 |   | TCP/80 - http | 2.05 | 35.49 | 37.54 | 0.02 | |||||||
| 37 | 192.168.6.95 |   | TCP/80 - http | 2.05 | 35.49 | 37.54 | 0.02 | |||||||
| 38 | 192.168.3.114 |   | TCP/80 - http | 2.05 | 35.49 | 37.54 | 0.02 | |||||||
| 39 | 192.168.6.83 |   | TCP/80 - http | 2.05 | 35.48 | 37.54 | 0.02 | |||||||
| 40 | 192.168.117.15 |   | TCP/80 - http | 2.05 | 35.48 | 37.54 | 0.02 | |||||||
| 41 | 192.168.4.44 |   | TCP/80 - http | 16.18 | 20.87 | 37.04 | 0.02 | |||||||
| 42 | 192.168.6.64 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 43 | 192.168.117.119 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 44 | 192.168.117.159 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 45 | 192.168.117.117 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 46 | 192.168.6.49 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 47 | 192.168.10.165 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 48 | 192.168.117.209 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 49 | 192.168.3.95 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| 50 | 192.168.6.91 |   | TCP/80 - http | 2.05 | 34.80 | 36.86 | 0.02 | |||||||
| Total |   | 2,935.10 | 188,469.25 | 191,404.36 | ||||||||||
| There were more records in this section but the reporting is limited to 50 | ||||||||||||||


| No | Host IP | Host Name | Protocols | Total | % | Comment |
| 1 | 192.168.101.20 |   | TCP/25 - smtp, ICMP/3 - unreach, UDP/123 - ntp, TCP/80 - http | 858.74 | 100.00 | |
| Total |   | 858.74 |
| No | Protocol | Sent | Received | Total | % | Comment | ||||||||
| 1 | TCP/80 - http | 8,132.35 | 294,639.69 | 302,772.05 | 93.17 | |||||||||
| 2 | TCP/25 - smtp | 21,297.03 | 441.26 | 21,738.29 | 6.69 | |||||||||
| 3 | TCP/3389 - ms rdp | 36.38 | 383.21 | 419.59 | 0.13 | |||||||||
| 4 | TCP/70 | 0.21 | 22.45 | 22.66 | 0.01 | |||||||||
| 5 | TCP/110 - pop3 | 5.15 | 11.79 | 16.93 | 0.01 | |||||||||
| 6 | ICMP/8 - ping | 1.98 | 0.00 | 1.98 | 0.00 | |||||||||
| 7 | TCP/33443 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 8 | TCP/33444 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 9 | TCP/139 - netbios | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 10 | TCP/33445 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 11 | TCP/33446 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 12 | TCP/33447 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 13 | TCP/33448 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 14 | TCP/443 - ssl-https | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 15 | TCP/33449 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 16 | TCP/445 - netbios | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 17 | UDP/38293 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 18 | UDP/2967 - symantec-av | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 19 | UDP/137 - netbios | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 20 | UDP/138 - netbios | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 21 | UDP/33440 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 22 | UDP/33441 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 23 | TCP/1026 - trojan | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 24 | TCP/1027 - icq | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| 25 | TCP/161 | 0.00 | 0.00 | 0.00 | 0 | |||||||||
| Total | 0.00 | 0.00 | 0.00 | |||||||||||
| There were more records in this section but the reporting is limited to 25 | ||||||||||||||
