TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

RealSecure has a bad habit of treating SYN-ACK packets the same as a
regular SYN packet (IMHO broken behavior), so it's not unusual for an event
to look like it's going the wrong way or even trigger twice. Look at the
source/destination ports closely and your traffic should make sense. In
general, trust the firewall logs since they will correctly reflect how TCP
traffic actually works.

-----Original Message-----
From: "Rodel Calvario" <[EMAIL PROTECTED]>
Sent: Friday, August 23, 2002 6:27 PM
To: [EMAIL PROTECTED]
Cc:
Subject: Real Secure logs (Sent by [EMAIL PROTECTED] on behalf of
"Rodel Calvario" <[EMAIL PROTECTED]> )



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------


Hi All,

Am a little confused in interpreting the RS logs that I have and comparing
them with the firewall logs.

As an example, I find an IP address from my RS logs to be the "source" but
when I go and check on the firewall logs, the same IP address doing the
same
service is now the "destination". Can anybody clarify this?

Thanks,

Rodel

_________________________________________________________________
Send and receive Hotmail on your mobile device: http://mobile.msn.com







Reply via email to