Hi Dan

At 00:07 30/07/02 -0700, Dan Harkless wrote:

>Of course weblet is still doing something I consider wrong -- it's saying
>the firewall is in red light / "ERROR" mode just because it has "251 denied
>or rejected packets".  Isn't this the whole point of a firewall, to deny and
>reject those packets?  How is this an "ERROR"?  At worst, it should be at
>"yellow alert".

It's possible to adjust this behaviour by changing the weblet's 
OK/warning/error thresholds.  I see you've got some advice on that already.

There's also the possibility that the bulk of those packets are from one or 
two harmless sources that you don't really need to worry about - it's 
common for cable/ADSL systems to spew forth all sorts of stuff of this 
type.  If this is the case it might be helpful to fiddle with your firewall 
rules so these things don't get logged in the first place.

I'd be inclined to do the latter, mainly because I only really want stuff 
that I have to think about in my logs and I find a lot of extra rows of 
harmless activity often make more important entries difficult to spot, but 
it's your firewall - you should do whichever you want.

cheers

Julian

-- 
[EMAIL PROTECTED]
www.ljchurch.co.uk



-------------------------------------------------------
This sf.net email is sponsored by: Dice - The leading online job board
for high-tech professionals. Search and apply for tech jobs today!
http://seeker.dice.com/seeker.epl?rel_code=31
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to