• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Interpreting Logs

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Logging and Reporting >> Interpreting Logs Page: [1]
Login
Message << Older Topic   Newer Topic >>
Interpreting Logs - 12.Jun.2005 1:26:00 PM   
dslaby

 

Posts: 24
Joined: 21.Jan.2003
Status: offline
I turned on log record type - Firewall or web proxy of my ISA 2004 server. Every two seconds there is a denied for NetBios Datagram, NetBios NameService, undefined IP Traffic and Allow NTP from ISA Server. The IP address being denied include 207.115.90.186 and 207.115.89.131. How do I react to these denied requests? Thanks.

Dan
Post #: 1
RE: Interpreting Logs - 12.Jun.2005 3:58:00 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
How do you want to react? The firewall is doing its job. Do you want to allow them? Do you want to deny them but not log them? If you don't want them logged, create a next to last deny rule that does not log. If you want to not log the undefined protocol, define it so that you can include it in the second last rule.

(in reply to dslaby)
Post #: 2
RE: Interpreting Logs - 12.Jun.2005 7:02:00 PM   
dslaby

 

Posts: 24
Joined: 21.Jan.2003
Status: offline
Thanks for your reply. Builds confidence in ISA.

(in reply to dslaby)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Logging and Reporting >> Interpreting Logs Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts