NetworkAdmin123
MIS
I've been given the task of monitoring what our firewall is doing. I not very familiar with this area so I thought I would see if I could get some help from you guys.
I've installed kiwi syslog and it is working fine. I even downloaded a trial of sawmill from sawmill.net. This is placing everything in a nice report format.
My main question is...what do I do with this data. I see some IP address that are being denied etc but how do I make sense of all this. I'll post some examples from my log below.
--------------------------------------------
2004-05-19 13:32:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1683 flags FIN ACK on interface outside
2004-05-19 13:32:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1683 flags ACK on interface outside
2004-05-19 13:33:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1684 flags FIN ACK on interface outside
2004-05-19 13:33:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1684 flags ACK on interface outside
2004-05-19 13:34:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1685 flags FIN ACK on interface outside
2004-05-19 13:34:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1685 flags ACK on interface outside
2004-05-19 13:34:23 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.141/4309 flags ACK on interface outside
2004-05-19 13:35:09 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2056 flags ACK on interface outside
2004-05-19 13:35:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1686 flags FIN ACK on interface outside
2004-05-19 13:35:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1686 flags ACK on interface outside
2004-05-19 13:35:46 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2094 flags ACK on interface outside
2004-05-19 13:35:46 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2094 flags ACK on interface outside
2004-05-19 13:35:46 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2094 flags ACK on interface outside
2004-05-19 13:36:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1687 flags FIN ACK on interface outside
2004-05-19 13:36:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1687 flags ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags PSH ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags PSH ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags FIN ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.73.86.30/80 to 192.168.1.147/1586 flags FIN PSH ACK on interface outside
2004-05-19 13:37:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1688 flags FIN ACK on interface outside
2004-05-19 13:37:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1688 flags ACK on interface outside
2004-05-19 13:38:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1689 flags FIN ACK on interface outside
2004-05-19 13:38:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1689 flags ACK on interface outside
I've installed kiwi syslog and it is working fine. I even downloaded a trial of sawmill from sawmill.net. This is placing everything in a nice report format.
My main question is...what do I do with this data. I see some IP address that are being denied etc but how do I make sense of all this. I'll post some examples from my log below.
--------------------------------------------
2004-05-19 13:32:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1683 flags FIN ACK on interface outside
2004-05-19 13:32:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1683 flags ACK on interface outside
2004-05-19 13:33:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1684 flags FIN ACK on interface outside
2004-05-19 13:33:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1684 flags ACK on interface outside
2004-05-19 13:34:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1685 flags FIN ACK on interface outside
2004-05-19 13:34:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1685 flags ACK on interface outside
2004-05-19 13:34:23 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.141/4309 flags ACK on interface outside
2004-05-19 13:35:09 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2056 flags ACK on interface outside
2004-05-19 13:35:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1686 flags FIN ACK on interface outside
2004-05-19 13:35:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1686 flags ACK on interface outside
2004-05-19 13:35:46 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2094 flags ACK on interface outside
2004-05-19 13:35:46 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2094 flags ACK on interface outside
2004-05-19 13:35:46 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.109.118.227/80 to 192.168.1.148/2094 flags ACK on interface outside
2004-05-19 13:36:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1687 flags FIN ACK on interface outside
2004-05-19 13:36:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1687 flags ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags PSH ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags PSH ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 65.197.236.54/80 to 192.168.1.147/1585 flags FIN ACK on interface outside
2004-05-19 13:37:13 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 216.73.86.30/80 to 192.168.1.147/1586 flags FIN PSH ACK on interface outside
2004-05-19 13:37:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1688 flags FIN ACK on interface outside
2004-05-19 13:37:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1688 flags ACK on interface outside
2004-05-19 13:38:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1689 flags FIN ACK on interface outside
2004-05-19 13:38:16 Local4.Critical 10.71.163.68 %PIX-2-106001: Inbound TCP connection denied from 166.102.165.50/110 to 192.168.1.156/1689 flags ACK on interface outside