08-13-2004 08:00 AM - edited 02-20-2020 11:34 PM
I am getting these messages from pix to the syslog servers.
I want to make sure what these messages are for???
I get alot of these messages (%PIX-2-106006).
Can somebody explain me and if there is action to be taken?
192.168.1.13 = IP address on outside interface
what are these ports for 6347,4246, 47782 and other port numbers given below
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 66.111.43.80/4246 to 192.168.1.13/50915 on interface outside
%PIX-2-106006: Deny inbound UDP from 66.111.43.80/4246 to 192.168.1.13/50915 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 81.56.45.111/6346 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 81.56.45.111/6346 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.34.249.178/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.34.249.178/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.34.249.178/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.34.249.178/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.34.249.178/6347 to 192.168.1.13/47782 on interface outside
%PIX-4-400011: IDS:2001 ICMP unreachable from 100.100.100.6 to 205.166.61.174 on interface inside
%PIX-2-106006: Deny inbound UDP from 220.255.39.76/38243 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 220.255.39.76/38243 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 220.255.39.76/38243 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 217.93.122.106/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 82.122.115.95/6347 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.38.19.45/12396 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.38.19.45/12396 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.38.19.45/12396 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.38.19.45/12396 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 80.38.19.45/12396 to 192.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 200.158.200.165/6347 to 92.168.1.13/47782 on interface outside
%PIX-2-106006: Deny inbound UDP from 81.56.45.111/6346 to 192.168.1.13/47782 on interface outside
08-13-2004 09:33 AM
Use the capture command to capture the packets. 192.168.1.13 is on the inside interface, right?
08-13-2004 09:51 AM
192.168.1.13 is the IP address of out side interface.
What is the use of capture command in this scenario?
08-13-2004 09:35 PM
Hi!
The port number Details for your information.
6347- These port used in TCP as well as UDP for peer to peer File Sharing. GNUTELLA.
4246 - this protocal used by below mentioned person
vrml-multi-use 4200-4299 VRML Multi User Systems
# Mitra <mitra@earth.path.net>
47782 - Port is unassigned.
better you block thses ports.
HTH.
Rgds
Vimal
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide