ganner_Hans
22-08-2002, 14:51
Здравствуй, уважаемый ALL!
Сегодня с утра такое вот волнение фиреволя. Интересно тем, что один процесс идет с разных IP ~ ч-з 10 сек. После прерывания и восстановления связи с инетом, все возобновилось. Кто-то может объяснить это природное явление? Привожу лог (хронология снизу, и спасибо, кто дочитал):
Firewall Event Log
________________
22.08.02 09:43:49.780 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:39.197 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:28.303 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:17.675 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:07.427 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:56.968 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:46.460 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:45.570 Interactive learning mode is disabled
22.08.02 09:42:45.570 Firewall is enabled. It has successfully processed a total of 37 rules
________________
22.08.02 09:42:39.706 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:26.733 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:16.539 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:06.416 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:41:56.457 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:41:52.618 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (tnt2.ladue.mo.da.uu.net)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:41:42.219 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (152.63.93.89)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
// здесь я прерывал связь с провом
//(адреса, сами понимаете, назначаются динамически)
________________
22.08.02 09:36:06.220 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (146.188.32.25)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:56.412 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (193.219.193.132)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:48.153 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (193.219.192.6)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:33.915 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (212.35.160.97)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:22.097 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (212.35.171.113)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:14.698 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.0.106)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:13.863 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.0.28)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:12.183 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.1.254)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:09.719 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.1.226)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 08:44:04.527 NDIS filtering is enabled
22.08.02 08:43:52.004 Interactive learning mode is enabled
22.08.02 08:43:52.004 Firewall is enabled. It has successfully processed a total of 37 rules
Сегодня с утра такое вот волнение фиреволя. Интересно тем, что один процесс идет с разных IP ~ ч-з 10 сек. После прерывания и восстановления связи с инетом, все возобновилось. Кто-то может объяснить это природное явление? Привожу лог (хронология снизу, и спасибо, кто дочитал):
Firewall Event Log
________________
22.08.02 09:43:49.780 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:39.197 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:28.303 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:17.675 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:43:07.427 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:56.968 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:46.460 Rule "Implicit block rule" blocked (1Cust66.tnt2.ladue.mo.da.uu.net,0). Details:
Inbound ICMP request
Local address is (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:45.570 Interactive learning mode is disabled
22.08.02 09:42:45.570 Firewall is enabled. It has successfully processed a total of 37 rules
________________
22.08.02 09:42:39.706 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:26.733 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:16.539 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:42:06.416 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:41:56.457 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (1Cust66.tnt2.ladue.mo.da.uu.net)
Message type is "Echo Reply"
Process name is "N/A"
________________
22.08.02 09:41:52.618 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (tnt2.ladue.mo.da.uu.net)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:41:42.219 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (152.63.93.89)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
// здесь я прерывал связь с провом
//(адреса, сами понимаете, назначаются динамически)
________________
22.08.02 09:36:06.220 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (146.188.32.25)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:56.412 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (193.219.193.132)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:48.153 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (193.219.192.6)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:33.915 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (212.35.160.97)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:22.097 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (212.35.171.113)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:14.698 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.0.106)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:13.863 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.0.28)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:12.183 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.1.254)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 09:35:09.719 This one time, the user has chosen to "block" communications. Details:
Inbound ICMP request
Local address (MY_ADDRESS)
Remote address is (213.130.1.226)
Message type is "Time Exceeded for a Datagram"
Process name is "N/A"
________________
22.08.02 08:44:04.527 NDIS filtering is enabled
22.08.02 08:43:52.004 Interactive learning mode is enabled
22.08.02 08:43:52.004 Firewall is enabled. It has successfully processed a total of 37 rules