F W L O G S U M     R E P O R T


Dropped and Rejected Entries
Sorted by service
Excluding services: (smtp)
Report generated on: Mon Jul 9 16:25:35 2007
Period for report data: 20 Oct 2001 at 17:21:03 to 26 Nov 2001 at 9:02:26
Period for matched data: 17 Nov 2001 at 14:10:43 to 26 Nov 2001 at 9:01:59

Total entries processed 18995
Entries matched on 299
Inbound traffic 18952
Outbound traffic 8
Control Messages 35
Entries Ignored 25
Alert Entries 2
Attack Types 0
Unique Attack URLs 0
Encrypted/Decrypted Entries 4
Unknown Entries 0

Colour Index
Standard Entries
Highlighted Entries
Alert Entries
Encrypted/Decrypted Entries

View Report Summary

FW1 Host Source Address Destination Address Service Count Rule
FWFOOMAIN01fwmain01.foo.com(http)dhcp-100-101-167-223.dhcp.foo.comtcp(1167)84
FWFOOMAIN01webfoogen1.foo.com(telnet)zeus.lab.foo.comtcp(1573)334
FWFOOMAIN01webfoogen1.foo.com(telnet)devel.lab.foo.comtcp(35338)94
FWFOOMAIN01webfoogen1.foo.com(telnet)devel.lab.foo.comtcp(38530)414
FWFOOMAIN01webfoogen1.foo.com(telnet)devel.lab.foo.comtcp(38567)424
FWFOOMAIN01gwt.lab.foo.com(22619)corelinkmain01.foo.comtcp(45)13
FWFOOMAIN01webfoogen1.foo.com(telnet)devel.lab.foo.comtcp(54924)74
FWFOOMAIN01dhcp-100-101-167-223.dhcp.foo.com(1234)fwmain01.foo.comtcp(FW1_mgmt)14
FWFOOMAIN01corelinkmain01.foo.com(11081)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11066)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01fwrtrmain01.foo.com(11046)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11061)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11060)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11050)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11075)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11053)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11051)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11082)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11049)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11000)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11044)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11073)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11055)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11045)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11065)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11041)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11079)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11047)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11059)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11048)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11056)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11064)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01fwrtrmain01.foo.com(11047)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11052)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11084)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11078)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11062)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11068)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11074)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11063)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11054)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01fwrtrmain01.foo.com(11000)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11067)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01fwrtrmain01.foo.com(11048)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11077)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11083)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11072)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11057)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11001)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11069)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11043)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01fwrtrmain01.foo.com(11050)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11070)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11042)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11046)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11058)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01fwrtrmain01.foo.com(11049)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01corelinkmain01.foo.com(11071)apollo.foo.comtcp(TACACSplus)14
FWFOOMAIN01webfoogen1.foo.com(1023)apollo.foo.comtcp(login)14
FWFOOMAIN01devel.lab.foo.com(1019)webfoogen1.foo.comtcp(login)14
FWFOOMAIN01devel.lab.foo.com(1021)webfoogen1.foo.comtcp(login)14
FWFOOMAIN01192.1.28.252(1023)webfoogen1.foo.comtcp(login)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(3167)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1325)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1316)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1322)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(3194)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1297)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1272)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1919)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1300)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(3178)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(3170)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1279)webwebmain01.foo.comtcp(nbsession)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(1916)webwebmain01.foo.comtcp(nbsession)14
FWFOOGW02gwt.lab.foo.com(1023)fwfoomain01.foo.comtcp(shell)13
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(990)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5300)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(917)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(910)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(939)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5212)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5303)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5209)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(937)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5298)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5305)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5306)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(971)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(997)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5206)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5301)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5207)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5297)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5302)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5304)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5205)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(908)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(921)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(951)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5208)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5308)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(954)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5307)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(5299)webwebmain01.foo.comtcp(sunrpc)14
FWFOOMAIN01dhcp-100-101-162-201.dhcp.foo.com(962)webwebmain01.foo.comtcp(sunrpc)14
INTERNETGWtest.lab.foo.com(6863)fwfoomain01-2tcp(tcpmux)13
INTERNETGWtest.lab.foo.com(6862)fwfoomain01.foo.comtcp(tcpmux)13
FWFOOMAIN01corelinkmain01.foo.com(64514)rtnw.foo.comtcp(telnet)14
FWFOOGW02dhcp-100-101-167-233.dhcp.foo.com.au(1586)fwfoomain01.foo.com.autcp(telnet)13
FWFOOMAIN01webfoogen1.foo.com(32819)apollo.foo.comtcp(telnet)14
FWFOOMAIN01fwrtrmain01.foo.com(63490)rtnw.foo.comtcp(telnet)14
FWFOOMAIN01gwt.lab.foo.com(22620)fwfoomain01.foo.comtcp(telnet)13
FWFOOGW02dhcp-100-101-167-233.dhcp.foo.com(1487)fwfoomain01.foo.comtcp(telnet)13
FWFOOMAIN01gwt.lab.foo.com(22620)fwfoomain01.foo.comtcp(telnet)13
FWFOOMAIN01dhcp-100-101-167-233.dhcp.foo.com(1588)fwfoomain01.foo.comtcp(telnet)13
FWFOOMAIN01fwrtrmain01.foo.com(12803)192.1.1.13tcp(telnet)14
FWFOOMAIN01corelinkmain01.foo.com(11266)192.1.1.13tcp(telnet)14
FWFOOMAIN01fwmain01.foo.com(1031)rtnw.foo.comtcp(telnet)14
FWFOOMAIN01gwt.lab.foo.com(22659)fwfoomain01.foo.comtcp(telnet)23
FWFOOMAIN01gwt.lab.foo.com(22657)fwfoomain01.foo.comtcp(telnet)13
FWFOOMAIN01dhcp-100-101-167-233.dhcp.foo.com(177)fwmain01.foo.comudp(177)24
FWFOOMAIN01gwt.lab.foo.com(65446)fwfoomain01.foo.comudp(33441)13
FWFOOMAIN01gwt.lab.foo.com(65446)fwfoomain01.foo.comudp(33442)13
FWFOOMAIN01gwt.lab.foo.com(65446)fwfoomain01.foo.comudp(33443)13
FWFOOMAIN01dhcp-100-101-167-233.dhcp.foo.com(nbname)fwfoomain01-2udp(nbname)14
INTERNETGWmlink.foo.co.uk(ntp-udp)ns4.foo.comudp(ntp-udp)13
FWFOOMAIN01mlink.foo.co.uk(ntp-udp)ns4.foo.comudp(ntp-udp)23
FWFOOMAIN01fwrtrmain01.foo.com(ntp-udp)ns4.foo.netudp(ntp-udp)13
FWFOOMAIN01fwrtrmain01.foo.com(ntp-udp)ns4.foo.comudp(ntp-udp)53
FWFOOMAIN01mlink.foo.co.uk(ntp-udp)ns4.foo.comudp(ntp-udp)43
FWFOOMAIN01mlink.foo.co.uk(ntp-udp)ns4.foo.netudp(ntp-udp)23
FWFOOGW02fwrtrmain01.foo.com(ntp-udp)ns4.foo.comudp(ntp-udp)23
FWFOOMAIN01fwrtrmain01.foo.com(ntp-udp)ns4.foo.comudp(ntp-udp)154
FWFOOGW02mlink.foo.co.uk(ntp-udp)ns4.foo.comudp(ntp-udp)23
FWFOOMAIN01fwrtrmain01.foo.com(ntp-udp)ns4.foo.comudp(ntp-udp)33

Summary Information

Firewall Server: Top 10 of 3
FWhost Count Of Total %
FWFOOMAIN0128996.66%
FWFOOGW0272.34%
INTERNETGW31.00%

Users/Source Addresses: Top 10 of 13
Source Count Of Total %
webfoogen1.foo.com13444.82%
corelinkmain01.foo.com4615.38%
dhcp-100-101-162-201.dhcp.foo.com4314.38%
fwrtrmain01.foo.com3411.37%
mlink.foo.co.uk113.68%
gwt.lab.foo.com103.34%
fwmain01.foo.com93.01%
dhcp-100-101-167-233.dhcp.foo.com51.67%
devel.lab.foo.com20.67%
test.lab.foo.com20.67%

Users/Destination Addresses: Top 10 of 15
Destination Count Of Total %
devel.lab.foo.com9933.11%
apollo.foo.com5217.39%
webwebmain01.foo.com4314.38%
ns4.foo.com3411.37%
zeus.lab.foo.com3311.04%
fwfoomain01.foo.com124.01%
dhcp-100-101-167-223.dhcp.foo.com82.68%
rtnw.foo.com31.00%
fwmain01.foo.com31.00%
ns4.foo.net31.00%

Service Usage: Top 10 of 21
Service Count Of Total %
tcp(TACACSplus)5016.72%
tcp(38567)4214.05%
tcp(38530)4113.71%
udp(ntp-udp)3712.37%
tcp(1573)3311.04%
tcp(sunrpc)3010.03%
tcp(telnet)144.68%
tcp(nbsession)134.35%
tcp(35338)93.01%
tcp(1167)82.68%

Rule Usage: Top 10 of 2
Rule Count Of Total %
Rule 426287.63%
Rule 33712.37%

Network Interface Usage: Top 10 of 6
Networks Count Of Total %
FWFOOMAIN01 hme1 (inbound)22976.59%
FWFOOMAIN01 hme0 (inbound)6020.07%
FWFOOGW02 hme1 (inbound)41.34%
FWFOOGW02 hme0 (inbound)31.00%
Internet Gateway (inbound)20.67%
Web Services Network (inbound)10.33%

Alert Types: Top 10 of 2
AlertType Count Of Total %
log10.33%
mail10.33%

Source Domains: Top 10 of 4
SrcDomain Count Of Total %
US Commercial28695.65%
United Kingdom113.68%
Australia10.33%
Unresolved10.33%

Destination Domains: Top 10 of 5
DestDomain Count Of Total %
US Commercial29197.32%
Network31.00%
Unknown20.67%
Unresolved20.67%
Australia10.33%

Daily Usage
Daily Count Of Total %
17Nov20015217.39%
18Nov2001113.68%
19Nov2001134.35%
20Nov20013411.37%
21Nov20013612.04%
22Nov20016120.40%
23Nov20016421.40%
25Nov2001103.34%
26Nov2001186.02%

24 Hour Period
Time Count Of Total %
0:00-1:00113.68%
1:00-2:0031.00%
2:00-3:00113.68%
3:00-4:0031.00%
4:00-5:00113.68%
5:00-6:0031.00%
6:00-7:00113.68%
7:00-8:0031.00%
8:00-9:00186.02%
9:00-10:0082.68%
10:00-11:00165.35%
11:00-12:003812.71%
12:00-13:0062.01%
13:00-14:00206.69%
14:00-15:005819.40%
16:00-17:00113.68%
17:00-18:0010.33%
18:00-19:00113.68%
19:00-20:00289.36%
20:00-21:00113.68%
21:00-22:0031.00%
22:00-23:00113.68%
23:00-24:0031.00%

Excluded Services

Service Count Of Entries %
smtp257.72%

Top of Report


fwlogsum Version: 5.0.3
Generated: Mon Jul 9 16:25:35 2007