Strange Logging behavior (Full Version)

All Forums >> [ISA Server 2004 Firewall] >> Logging and Reporting



Message


rpetruni -> Strange Logging behavior (17.Mar.2005 9:53:00 AM)

There is a ? above my head regarding logging.
I'm using MSDE logging, and if i filter some IP address to see what packets are blocked or not blocked i see 2 things that i'm not able to explain.
1. There are packets allowed trough firewall with empty rule ??? How can packet pass trough firewall not beeing evaluated by any rule?
2. There are packets with status allowed, by DEFAULT rule, wich is Deny ALL ????

Could somebody explain to me what is going on, or point me to QB article. Am i the only one with those odd loggings?

Thanks

Robert




tshinder -> RE: Strange Logging behavior (17.Mar.2005 2:36:00 PM)

Hi Robert,

I've never seen packets allowed by the default rule. What type of traffic is this?

Thanks!
Tom




rpetruni -> RE: Strange Logging behavior (20.Mar.2005 8:51:00 PM)

HTTP trafic...

Robert




rpetruni -> RE: Strange Logging behavior (22.Mar.2005 10:13:00 AM)

This is part of my log....

klik here to see it




Page: [1]