From: Zakai Kinan (titanyen2000~AT~yahoo.com)
Date: Thu Feb 24 2005 - 00:04:23 CET
In the packet source host report, what is the other category so big? On my report, it constitutes 95% blocking. what is the threshold under which it will not show an IP/host? I can't send the log due security restrictions.
> * Zakai Kinan <titanyen2000~AT~yahoo.com> [2005-02-20
> > The information that fwanalog spits out is not
> intuitive. It does not
> > tell me the IP addresses that are attacking my pix
> firewall. Am I
> does it look like the sample page at
> http://tud.at/programm/fwanalog/sample-report.html ?
> There should be a "Blocked packet report" about the
> attacked IPs and ports
> and a list of attackers in the "Packet Source Host
> If you don't get the right output, you could send me
> a part of your log in
> private e-mail and I could take a look at it.
This archive was generated by hypermail 2.1.5 : Sat Feb 26 2005 - 18:02:04 CET