"Steve" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Ron,
>
> Thanks for the log. My old Netgear FR314 provides, IMHO, a more useful
log:
>
> 06/19/2004 00:09:37.208 - TCP connection dropped - Source:221.125.35.230,
> 2178, WAN - Destination:xxx.xxx.xxx.xxx, 5554, WAN
> ...
> It is a real shame that the newer, more capable models don't provide this
> information. Personally, I value the logging more than the later bells and
> whistles.
>
>
> "Ron Bandes" <RunderscoreBandes @yah00.com> wrote in message
> news:K_5Bc.28515$(E-Mail Removed) et...
> > "Steve" <(E-Mail Removed)> wrote in message
> > news:(E-Mail Removed)...
> Would
> > > somebody with a Belkin F5D7230-4 care to report on its logging
> functions,
> > > maybe even supply a sample?
> >
> > Here's a Belkin log:
> >
> > System log:
> > Sat Jun 19 20:25:01 2004 -WAN DHCP Client Connected IP xxx.xxx.xxx.xxx
> > Sat Jun 19 21:39:11 2004 -67.86.17.18 logout
> > Sat Jun 19 21:39:31 2004 -67.86.17.18 login
> >
> > Firewall log:
> > Sat Jun 19 21:37:44 2004 1 Blocked by DoS protection 10.39.32.1
> >
> > Ron Bandes, CCNP, CTT+, etc.
Here is a log from my old SMC Barricade 7004BR:
Sunday, June 20, 2004 10:22:07 PM Unrecognized access from
202.103.45.229:2823 to TCP port 9898
Sunday, June 20, 2004 10:38:08 PM Unrecognized access from
63.127.192.137:6587 to UDP port 1026
Sunday, June 20, 2004 10:42:15 PM 192.168.123.109 login successful
Here is a log from my newer SMC 2804WBR:
Security Log
06/20/2004 22:23:11 192.168.117.105 login success
06/20/2004 21:13:30 NTP Date/Time updated
06/20/2004 15:14:24 NTP Date/Time updated
06/20/2004 09:15:18 NTP Date/Time updated
06/20/2004 03:16:12 NTP Date/Time updated
06/19/2004 21:17:06 NTP Date/Time updated
06/19/2004 15:17:59 NTP Date/Time updated
06/19/2004 09:18:53 NTP Date/Time updated
06/19/2004 03:19:47 NTP Date/Time updated
06/07/2004 21:57:40 192.168.117.104 logout
06/07/2004 21:54:05 192.168.117.104 login success
DHCP Client Log
01/01/2002 00:00:01 DHCP Client: Receive Ack from 192.168.123.254,Lease
time=3600000
01/01/2002 00:00:01 DHCP Client: Domain name =
01/01/2002 00:00:01 DHCP Client: Send Request,Request IP=192.168.123.108
01/01/2002 00:00:01 DHCP Client: Receive Offer from 192.168.123.254
01/01/2002 00:00:01 DHCP Client: Domain name =
01/01/2002 00:00:00 DHCP Client: Send Discover
The 2804WBR never sees attacks because it's behind the 7004BR. Some emails
sent by the 2804WBR firewall because it thought it detected an outbound
attack:
--- begin firewall email
Dear User
Your router has detected and protected you against an attempt to gain access
to your network. This may have been an attempted hacker intrusion, or
perhaps just your Internet Service Provider doing routine network
maintenance.
Most of these network probes are nothing to be worried about - these types
of random probes should NOT be reported, but you may want to report repeated
intrusions attempts. Save this email for comparison with future alert
messages.
Your router Alert Information
Time: 05/20/2004, 17:41:10
Message: IP Spoofing
Source: 192.168.117.104, 138
Destination:192.168.117.255, 138 (from WAN Inbound)
Visit the UXN Combat Spam web site to get more detailed information about
the intruder -
http://combat.uxn.com/
1. Type the intruder's IP address into the IP WHOIS search engine
2. Click the Query Button
3. Detailed network and administration information will be displayed
--- end firewall email
--- begin firewall email
Dear User
Your router has detected and protected you against an attempt to gain access
to your network. This may have been an attempted hacker intrusion, or
perhaps just your Internet Service Provider doing routine network
maintenance.
Most of these network probes are nothing to be worried about - these types
of random probes should NOT be reported, but you may want to report repeated
intrusions attempts. Save this email for comparison with future alert
messages.
Your router Alert Information
Time: 05/16/2004, 01:55:35
Message: Smurf
Source: 192.168.117.104
Destination:66.218.66.255, Type:8, Code:0 (from LAN Inbound)
Visit the UXN Combat Spam web site to get more detailed information about
the intruder -
http://combat.uxn.com/
1. Type the intruder's IP address into the IP WHOIS search engine
2. Click the Query Button
3. Detailed network and administration information will be displayed
--- end firewall email
--- begin firewall email
Dear User
Your router has detected and protected you against an attempt to gain access
to your network. This may have been an attempted hacker intrusion, or
perhaps just your Internet Service Provider doing routine network
maintenance.
Most of these network probes are nothing to be worried about - these types
of random probes should NOT be reported, but you may want to report repeated
intrusions attempts. Save this email for comparison with future alert
messages.
Your router Alert Information
Time: 03/31/2004, 21:26:05
Message: SYN Flood to Host
Source: 192.168.117.103, 1390
Destination:198.62.124.7, 80 (from WAN Outbound)
Visit the UXN Combat Spam web site to get more detailed information about
the intruder -
http://combat.uxn.com/
1. Type the intruder's IP address into the IP WHOIS search engine
2. Click the Query Button
3. Detailed network and administration information will be displayed
--- end firewall email
Ron Bandes, CCNP, CTT+, etc.