Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Advice Needed on system-critical messages

Status
Not open for further replies.

Coldfuzion

IS-IT--Management
May 7, 2002
30
US
On my NS 50 i am getting constant notifications, every 20 to 40 min stating:

[00001] 2006-05-12 16:27:30 [Root]system-critical-00433: EXE file blocked! From 208.172.128.222:80 to xx.xxx.xx.xxx:12491, proto TCP (zone Untrust, int ethernet3).
Occurred 1 times.

The source IP changes somewhat, but tracing the IP shows that they are always from Savvis, Microsoft or Limlight. The xxx IP is my NS 50.
My question is, are these harmless? Should i uncheck the .exe and .zip screen block and allow these through before the constant notifications drive me nuts?

Here are a few more examples:

[00001] 2006-05-12 16:47:30 [Root]system-critical-00433: EXE file blocked! From 208.172.64.254:80 to xx.xx:12498, proto TCP (zone Untrust, int ethernet3).
Occurred 1 times.
[00002] 2006-05-12 16:35:27 [Root]system-critical-00433: EXE file blocked! From 206.24.192.252:80 to xx.xx:12600, proto TCP (zone Untrust, int ethernet3).
Occurred 1 times.
[00003] 2006-05-12 16:35:15 [Root]system-critical-00433: EXE file blocked! From 68.142.79.97:80 to xx.xx:1964, proto TCP (zone Untrust, int ethernet3).
Occurred 1 times.

Thanks in advance.
 
Hello,

We filter .exe's as well, I would leave it unless your Company policy permits these types of attachements. As far as the alerts, we moved to a SYSLOG and alert as needed via SMTP.

Rgds,

John
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top