while your in the log viewer, you can highlight the log entry and go to "select" then "block intruder" and there you can have options to block intruder/destination IP.  Be careful though, there is no listing of user's you have blocked through this.  If you've blocked somebody accidentally, you can clear your FWSAM (FW Suspicious Actividty Monitor) by going to $FWDIR\bin and running "fw sam -D".  This will clear all entries for blocked intruder.
 
 
----- Original Message -----
From: x man
Sent: Wednesday, April 11, 2001 4:13 AM
Subject: [FW1] configure fw

i have fw-1 box 4.1
someone out there tried to compromise my network, and i can see from fw-log
my quetions are,
1. can i block some IP which action "drop" w/o create rule in policy editor.
2. sometimes when i retrived logs , i got "management Gui"(console for fw) is in source and point to destination  IP public, which service netbios-ns. Is it dangerous or i create wrong rule ?"
tks
 
 

Reply via email to