{\rtf1\ansi\ansicpg1252\deff0\deflang1033{\fonttbl{\f0\fnil\fprq2\fcharset0 MS Sans Serif;}}
\viewkind4\uc1\pard\f0\fs20 We have seen several issues with the sonicwall, where it apears from our logs, that the firewall thinks it is being DOSd, and starts dropping packets.
\par
\par Don't know what happened with these issues when we geve these customers the logs, and they went to SonicWall.
\par
\par Jason Tyler
\par Windows Media SDK/Developer Support
\par
\par This posting is provided "AS IS" with no warranties, and confers no rights.
\par You assume all risk for your use. \'a9 2003 Microsoft Corporation. All rights
\par reserved.
\par
\par }
Re: Strange WAN Activity ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ... (microsoft.public.win2000.security)
Re: Winvnc hack! [25 KB] ... came in from a service such as IIS that logs IP address. ... Check your IIS... Some firewall software such as ... You can also use the NETSTAT -A command that comes with Windows to look at ... (microsoft.public.win2000.security)
RE: [fw-wiz] Log checking? ... tend to evaluate where and what logging is important in a different light. ... I've been happy to analyze a year's worth of firewall denied logs,... have denied firewall traffic logs or denied logs with any relevant data. ... (Firewall-Wizards)
Re: SonicWall firewall question ... >> 6300 concurrent connections is a significant chunk of traffic.. ... >> especially for someone considering hosting "a few internet servers...... you miss my original point in that a firewall is not the only ... >I was talking about the original SonicWall Pro now called the SonicWall Pro ... (comp.security.firewalls)
Re: false portscan alarm ... What is the reason of that treffic? ... and the browser and/or the "personal firewall" had decided to close those ... which each have a local source port above 1024 opened outgoing to port 80 ... I've had a dig through my own PIX logs, and while there is nothing for today ... (comp.security.firewalls)