Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Logging outgoing/incomming address'

 
Thread Tools Search this Thread
Old 02-28-2005, 01:09 AM   #1
Default Logging outgoing/incomming address'


Hi all,
How or what program can I use to log all outgoing and incomming
address' simular to the one that was on Atguard firewall. The
firewall no longer logs using XP.

Thanks for any suggestions,
George



george
  Reply With Quote
Old 03-01-2005, 05:33 AM   #2
Michael J. Pelletier
 
Posts: n/a
Default Re: Logging outgoing/incomming address'
george wrote:

> Hi all,
> How or what program can I use to log all outgoing and incomming
> address' simular to the one that was on Atguard firewall. The
> firewall no longer logs using XP.
>
> Thanks for any suggestions,
> George



I am not sure if linux/BSDs are your thing but they can do it with a simple
"log" command. If you use syslog you can also archive the data. And if you
are really fancy, you can import the data in MySQL...and if you are...well,
i guess that is enough for today.

Michael


Michael J. Pelletier
  Reply With Quote
Old 03-02-2005, 04:14 PM   #3
george
 
Posts: n/a
Default Re: Logging outgoing/incomming address'
Thanks Michael

I found a program called Quick System
toos. It is a port monitor. While it doesn't make a log, it does
show connections in real time. It gives me a chance to make
corrections in the hosts file.

George
On Mon, 28 Feb 2005 21:33:53 -0800, "Michael J. Pelletier"
<> wrote:

>george wrote:
>
>> Hi all,
>> How or what program can I use to log all outgoing and incomming
>> address' simular to the one that was on Atguard firewall. The
>> firewall no longer logs using XP.
>>
>> Thanks for any suggestions,
>> George

>
>
>I am not sure if linux/BSDs are your thing but they can do it with a simple
>"log" command. If you use syslog you can also archive the data. And if you
>are really fancy, you can import the data in MySQL...and if you are...well,
>i guess that is enough for today.
>
>Michael




george
  Reply With Quote
Old 03-03-2005, 05:09 AM   #4
winged
 
Posts: n/a
Default Re: Logging outgoing/incomming address'
Michael J. Pelletier wrote:
> george wrote:
>
>
>>Hi all,
>>How or what program can I use to log all outgoing and incomming
>>address' simular to the one that was on Atguard firewall. The
>>firewall no longer logs using XP.
>>
>>Thanks for any suggestions,
>>George



The Symantec Firewall logs all completed and blocked connections,
inbound or outbound, identifies blocked content, Intrusion detection
triggers, Blocked and allowed privacy information (type of release and
to whom), IP logs including all local dynamic and static IP's that have
been used when, logs all firewall configuration and status changes,
Historical web history, and user and system defined alerts and which
rule triggered the alert. These are separate logs and log max size is
user defined. Logs rollover once max size is reached (problematic for
archiving as duplicate data is assured when logs are backed up. While
this deficiency is not unique I am not sure I need to duplicate the data
on my incremental |

You can also enable the XP ICF to log.

To enable the XP firewall logging:
- Start - Control Panel - Network Connections
- Right click on your current active network or dial-up connection and
choose properties
- Click on the Advanced Tab and check the box under Internet Connection
Firewall
- At the bottom of the same page click on the Settings button
- Under Security Logging check both boxes
- Under Log File Options leave the default path alone
- Under size you can change the max size of the file if so desired.

There are a number of free log review and analysis utilities that makes
the log review less painful on the net. The XP ICF uses the extended
log file format established by the WC3. Any viewer that is capable of
reviewing this format may be used.

If you choose this route, learn to use the manual methods (using msi,
policy or script) to control the XP ICF configuration. The standard MS
simplified interface lacks the finite control one needs to properly
manage connections, however the firewall and logging is capable.
Application access may also be accessed from outside the MS interface
and rules established for more finite port control.

Winged


winged
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
I have become rich in 30 days lemony-snicket A+ Certification 2 09-07-2009 03:01 PM
Site to Site VPN MTU issue? chary Hardware 0 08-27-2008 02:05 AM
Spoke to Spoke Enhanced Config (ASA-PIX) NEED HELP ASAP!! T-Mak Hardware 1 10-27-2006 11:56 AM
This is incredible! jc_ice DVD Video 1 08-13-2006 10:47 AM
Address Bus and External Data Bus Confusion LoXodonte A+ Certification 1 04-18-2006 10:09 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46