Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | firewall log

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service

firewall log
Reply
 
Thread Tools
Old 16-12-2003, 12:36   #1
Frank
Inactive
 
Join Date: Jun 2003
Location: Toronto, Canada
Services: Beanfield 50/50 FTTH and iPTV
Posts: 1,756
Frank has a golden auraFrank has a golden auraFrank has a golden auraFrank has a golden aura
Frank has a golden auraFrank has a golden aura
firewall log

Any ideas what all these outgoing packets are from? All my apps seem to work fine. Open during this is: Winamp, mIRC, IE, Azureus, MSN Messenger.
Frank is offline   Reply With Quote
Advertisement
Old 16-12-2003, 12:38   #2
Defiant
Guest
 
Posts: n/a
Re: firewall log

I think you've just answered your own question
  Reply With Quote
Old 16-12-2003, 12:40   #3
Frank
Inactive
 
Join Date: Jun 2003
Location: Toronto, Canada
Services: Beanfield 50/50 FTTH and iPTV
Posts: 1,756
Frank has a golden auraFrank has a golden auraFrank has a golden auraFrank has a golden aura
Frank has a golden auraFrank has a golden aura
Re: firewall log

eh?
Frank is offline   Reply With Quote
Old 16-12-2003, 12:41   #4
Defiant
Guest
 
Posts: n/a
Re: firewall log

Quote:
Originally Posted by Keyser
eh?

Quote:
Open during this is: Winamp, mIRC, IE, Azureus
  Reply With Quote
Old 16-12-2003, 12:44   #5
Frank
Inactive
 
Join Date: Jun 2003
Location: Toronto, Canada
Services: Beanfield 50/50 FTTH and iPTV
Posts: 1,756
Frank has a golden auraFrank has a golden auraFrank has a golden auraFrank has a golden aura
Frank has a golden auraFrank has a golden aura
Re: firewall log

Nah I have rules to allow all these applications. Like I said, they all work fine (so aren't being blocked). I'm wondering what all the other traffic is. None of the ports in the log I recognise being from any of the applications I'm using.
Frank is offline   Reply With Quote
Old 16-12-2003, 12:46   #6
Defiant
Guest
 
Posts: n/a
Re: firewall log

What firewall are you using. If its zonealarm it should tell you exactly whats using the internet at this time
  Reply With Quote
Old 16-12-2003, 12:47   #7
Paul K
Inactive
 
Paul K's Avatar
 
Join Date: Jun 2003
Location: Essex innit
Age: 52
Services: Sky HD + 16Mb ADSL BT Telephone
Posts: 15,735
Paul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered stars
Paul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered stars
Re: firewall log

Has this acivity only just started? If so have you done a system scan for virus/ spyware etc?
Paul K is offline   Reply With Quote
Old 16-12-2003, 12:48   #8
Jon M
Inactive
 
Jon M's Avatar
 
Join Date: Oct 2003
Location: East Midlands
Age: 48
Services: Rural BB - Radio Link via Virgin Fibre
Posts: 2,947
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Send a message via MSN to Jon M
Re: firewall log

just because they work doesn't mean they're not responsible for that traffic.. for example.. p2p software will be receiving packets for download (incoming rules).. but what you see above could be generated by the program to build your available file listing (outgoing rule)

just an example
Jon M is offline   Reply With Quote
Old 16-12-2003, 12:50   #9
Defiant
Guest
 
Posts: n/a
Re: firewall log

Quote:
Originally Posted by s1lv3r
just because they work doesn't mean they're not responsible for that traffic.. for example.. p2p software will be receiving packets for download (incoming rules).. but what you see above could be generated by the program to build your available file listing (outgoing rule)

just an example

Correct, I have logs like that when I've had flashfxp,mirc,kazaa and other things all running at once
  Reply With Quote
Old 16-12-2003, 12:51   #10
Nemesis
Inactive
 
Join Date: Jun 2003
Location: Surrey
Age: 59
Services: Virgin stuff
Posts: 6,407
Nemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny star
Nemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny star
Send a message via MSN to Nemesis
Re: firewall log

lookup 62.62.236.85 ... 85.236.62.62.9nanterr1-0-ro-bas-1.9tel.net
lookup 81.134.64.62 ... host81-134-64-62.in-addr.btopenworld.com
lookup 82.65.123.214 ... lns-p19-18-82-65-123-214.adsl.proxad.net
lookup 12.249.3.205 ... 12-249-3-205.client.attbi.com
lookup 12.215.41.59 ... 12-215-41-59.client.mchsi.com
lookup 24.165.230.36 ... 36.230.165.24.cfl.rr.com
Nemesis is offline   Reply With Quote
Old 16-12-2003, 12:53   #11
Paul K
Inactive
 
Paul K's Avatar
 
Join Date: Jun 2003
Location: Essex innit
Age: 52
Services: Sky HD + 16Mb ADSL BT Telephone
Posts: 15,735
Paul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered stars
Paul K is seeing silvered starsPaul K is seeing silvered starsPaul K is seeing silvered stars
Re: firewall log

Yep p2p can upset your logs, is the only thing that shows in mine since I sit behind a router LOL. Its normally the software trying to re-connect to sources previously used and also trying to find new ones. Not everyone uses the standard ports since they get blocked by ISP's so strange ports can show up.
Paul K is offline   Reply With Quote
Old 16-12-2003, 12:55   #12
Jon M
Inactive
 
Jon M's Avatar
 
Join Date: Oct 2003
Location: East Midlands
Age: 48
Services: Rural BB - Radio Link via Virgin Fibre
Posts: 2,947
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Send a message via MSN to Jon M
Re: firewall log

it's worth doing a sweep of your system with an anti-trojan/spyware tool anyway.. just to be sure.. in fact i'd do that regularly regardless of any unusual activity
Jon M is offline   Reply With Quote
Old 16-12-2003, 13:03   #13
Frank
Inactive
 
Join Date: Jun 2003
Location: Toronto, Canada
Services: Beanfield 50/50 FTTH and iPTV
Posts: 1,756
Frank has a golden auraFrank has a golden auraFrank has a golden auraFrank has a golden aura
Frank has a golden auraFrank has a golden aura
Re: firewall log

Thanks for all the replies guys. I'm using Deerfield Visnetic firewall and have had logs like this for a while now. I've just decided that I wanna know why the log is so large and try and cut down the pure size of the log!

I'm thinking it's something like s1lv3r suggested, but I've opened all the ports I believe I'm supposed to for p2p (see attached tcp ruleset).

I've done a spyware scan and its clean.
Frank is offline   Reply With Quote
Old 16-12-2003, 13:12   #14
Jon M
Inactive
 
Jon M's Avatar
 
Join Date: Oct 2003
Location: East Midlands
Age: 48
Services: Rural BB - Radio Link via Virgin Fibre
Posts: 2,947
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Send a message via MSN to Jon M
Re: firewall log

setup looks fine to me.. the bittorrent one is the only one that looks like it may be responsible.. i notice you've restricted it's outbound ports to the 6881-6999 range.. (which is the right thing to do).. on that basis i'd be unsurprised to see that sort of log.. especially if you can't specify specific ports within the program

edit: just noticed overnet.. same applies there /edit
Jon M is offline   Reply With Quote
Old 16-12-2003, 13:31   #15
Frank
Inactive
 
Join Date: Jun 2003
Location: Toronto, Canada
Services: Beanfield 50/50 FTTH and iPTV
Posts: 1,756
Frank has a golden auraFrank has a golden auraFrank has a golden auraFrank has a golden aura
Frank has a golden auraFrank has a golden aura
Re: firewall log

Fair enuf. Cheers for the answers. I'd rather live with a big log than an unsecure system
Frank is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 19:24.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum