TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
RealSecure has a bad habit of treating SYN-ACK packets the same as a regular SYN packet (IMHO broken behavior), so it's not unusual for an event to look like it's going the wrong way or even trigger twice. Look at the source/destination ports closely and your traffic should make sense. In general, trust the firewall logs since they will correctly reflect how TCP traffic actually works. -----Original Message----- From: "Rodel Calvario" <[EMAIL PROTECTED]> Sent: Friday, August 23, 2002 6:27 PM To: [EMAIL PROTECTED] Cc: Subject: Real Secure logs (Sent by [EMAIL PROTECTED] on behalf of "Rodel Calvario" <[EMAIL PROTECTED]> ) TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- Hi All, Am a little confused in interpreting the RS logs that I have and comparing them with the firewall logs. As an example, I find an IP address from my RS logs to be the "source" but when I go and check on the firewall logs, the same IP address doing the same service is now the "destination". Can anybody clarify this? Thanks, Rodel _________________________________________________________________ Send and receive Hotmail on your mobile device: http://mobile.msn.com
