Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.200 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-16-2008, 11:15 AM
bitonw's Avatar
Senior Member
 
Join Date: Jun 2004
Location: UK, Europe
Posts: 156
Default v7.193 IM/P2P wrong reports; tencent_qq, bittorrent & winny

version v7.193 is now reporting IM/P2P; tencent_qq, bittorrent & winny while not in use on my network...
__________________
asl latest version jetway J7F2WE2G / 1024mb / sata 120gb / AD3RTLANP / cubid 3688

bit4net
bt
  #2 (permalink)  
Old 05-16-2008, 01:45 PM
Junior Member
 
Join Date: Apr 2008
Posts: 8
Default

Hi bitnow,

i know that there are still some false positives in the reporting ....
Can you tell what possibly is classiefied wrong or what do you have running in your network?
  #3 (permalink)  
Old 05-17-2008, 10:49 PM
bitonw's Avatar
Senior Member
 
Join Date: Jun 2004
Location: UK, Europe
Posts: 156
Default

on my network i only have a dualphone what is an skype phone connected in my dmz. it's on a fixed port.
__________________
asl latest version jetway J7F2WE2G / 1024mb / sata 120gb / AD3RTLANP / cubid 3688

bit4net
bt
  #4 (permalink)  
Old 05-18-2008, 02:37 PM
Gert Hansen's Avatar
Wizard
 
Join Date: Nov 2000
Location: Karlsruhe, Germany
Posts: 1,242
Default

Can you check the im/p2p log file so we can see which kind of packets triggered the false alarm. I am interrested the ip addresses as well as the ports, this way we could see which kind of connection it has been.

thx Gert
  #5 (permalink)  
Old 05-21-2008, 11:13 AM
bitonw's Avatar
Senior Member
 
Join Date: Jun 2004
Location: UK, Europe
Posts: 156
Default logs

dear gert,

sorry for the delay was a bit busy. have added zip to the file to upload.
Attached Files
File Type: zip afc-2008-05-15.log.gz.zip (33.6 KB, 4 views)
File Type: zip afc-2008-05-16.log.gz.zip (66.3 KB, 3 views)
__________________
asl latest version jetway J7F2WE2G / 1024mb / sata 120gb / AD3RTLANP / cubid 3688

bit4net
bt
  #6 (permalink)  
Old 05-22-2008, 11:29 AM
Gert Hansen's Avatar
Wizard
 
Join Date: Nov 2000
Location: Karlsruhe, Germany
Posts: 1,242
Default

Thanks bitonw,

i will take a look at it.

thx Gert
  #7 (permalink)  
Old 05-22-2008, 05:59 PM
Gert Hansen's Avatar
Wizard
 
Join Date: Nov 2000
Location: Karlsruhe, Germany
Posts: 1,242
Default

Hi bitonw,

i looked at your logfile and analyzed it.
It shows that four im/p2p protocol's are detected.
Skype from the internal host 172.27.7.30, i assume that is your skypephone.
Bittorrent from the internal host 172.17.7.197, i assume that is our bittorrent client for download ASG images .

the first false postive detections WinNYwas a packet sent from the internal host 172.27.7.32 with source port 80, therefore i assume this is a webserver.
As i don't know what kind of content gets downloaded from there. If you plan to further investigate your need to check the webserver logfile what kind of data has been downloaded at this timeframe 2008:05:15-06:09:03 from a client with the ip address 90.199.99.147.
If possible please send me the URL so i can verify this false postive on my system (you use the PersonalMessage for that)

The second false postive QQ, was a packet, and now this is strange, from the src ip 172.27.7.31 to the destination ip 172.27.7.31 with the source port of 53.
Is this your DNS server? Do you have any special NAT settings?

in both cases it was a single packet.

i hope this helps,
thx
Gert
  #8 (permalink)  
Old 05-26-2008, 08:27 PM
bitonw's Avatar
Senior Member
 
Join Date: Jun 2004
Location: UK, Europe
Posts: 156
Default

hallo gert,

pm send

thx,
bt
__________________
asl latest version jetway J7F2WE2G / 1024mb / sata 120gb / AD3RTLANP / cubid 3688

bit4net
bt
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 04:49 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.