somecompany Firewall reports


Last 24 Hours Top 25 Firewall ALL connetions ordered by Src_IP

Count action src_ip dst_port dst_ip messages
8936 reject X.X..24.83 (X.X..24.83) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
3505 accept X.X..18.201 (X.X..18.201) [] [i] 0 X.X.254.13 (X.X.254.13) [] [i] 0
2775 accept X.X.40.41 (X.X.40.41) [] [i] smtp X.X..6.64 (X.X..6.64) [] [i] 0
2478 accept X.X.40.40 (X.X.40.40) [] [i] http 63.71.8.41 (prod-www.asdasdas.com) [] [i] 0
2458 drop X.X..6.10 (X.X..6.10) [] [i] 0 X.X24.226 (X.X24.226) [] [i] Local interface address spoofing
2437 accept X.X.40.42 (X.X.40.42) [] [i] smtp X.X..6.64 (X.X..6.64) [] [i] 0
2286 reject X.X.4.109 (r1603-pc-5th-cd.somecompany.com) [] [i] http 209.202.141.212 (consumerinput.com) [] [i] 0
2210 accept X.X..6.51 (whatsup.somecompany.com) [] [i] 0 X.X.40.51 (wadasdas01.somecompany.com) [] [i] 0
1889 accept X.X..16.208 (00034728c3e4.somecompany.com) [] [i] 0 129.105.253.9 (lev-mdf-7-ser-2-1.northwestern.edu) [] [i] 0
1782 accept X.X..2.10 (X.X..2.10) [] [i] 8585 192.168.204.30 (192.168.204.30) [] [i] 0
1782 accept X.X.30.7 (X.X.30.7) [] [i] smtp X.X..32.44 (asdaDJAh2.somecompany.com) [] [i] 0
1509 accept 192.168.194.108 (192.168.194.108) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
1255 accept X.X.40.31 (adasdaspf02.somecompany.com) [] [i] MS-SQL-Server X.X..32.52 (sql2kadasdasdata.somecompany.com) [] [i] 0
1176 accept X.X..7.88 (r1603-pc-6-dl1.somecompany.com) [] [i] smtp 66.33.213.158 (a1.postal.mail.dreamhost.com) [] [i] 0
1089 accept X.X.40.30 (adasdaspf01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
912 accept X.X..18.77 (somecompanysim.somecompany.com) [] [i] 0 X.X.40.56 (adasdass.somecompany.com) [] [i] 0
895 accept X.X..37.124 (adasdas518.somecompany.com) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
843 accept 204.153.216.45 (204.153.216.45) [] [i] 0 X.X17.8 (im.testadasdas.somecompany.com) [] [i] 0
750 drop 65.103.130.128 (65-103-130-128.spkn.qwest.net) [] [i] rpc_135 X.X17.8 (im.testadasdas.somecompany.com) [] [i] 0
749 reject X.X..20.177 (X.X..20.177) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
727 accept 10.19.1.2 (w2k-hpov-01.testadasdas.somecompany.com) [] [i] snmp-read X.X..254.13 (somecompany-perimeter2.testadasdas.somecompany.com) [] [i] 0
725 reject X.X..4.110 (X.X..4.110) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
668 reject X.X..30.85 (X.X..30.85) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
633 accept X.X.52.32 (hph-mfxp-01.somecompany.com) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
570 accept 67.38.111.245 (adsl-67-38-111-245.dsl.chcgil.ameritech.net) [] [i] smtp x.x.x.135 (x.x.x.135) [] [i] 0
543 accept X.X..38.59 (X.X..38.59) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
541 accept X.X..38.51 (X.X..38.51) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
530 accept X.X.3.51 (X.X.3.51) [] [i] http 199.230.128.100 (vwww.cardinal.com) [] [i] 0
520 accept X.X..12.35 (dmsexp001.inw.com) [] [i] 1238 192.168.0.12 (192.168.0.12) [] [i] 0
510 accept X.X.40.20 (adasdas01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
506 accept X.X.30.100 (adasdas100.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
490 drop 24.36.39.101 (d36-39-101.home1.cgocable.net) [] [i] https X.X17.8 (im.testadasdas.somecompany.com) [] [i] 0
487 accept X.X.40.21 (adasdas02.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
479 accept X.X.30.200 (somecompanypathadasdas.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
460 accept X.X.40.45 (adasdasadasdas01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
456 accept X.X.40.46 (adasdasadasdas02.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
455 accept X.X..38.139 (X.X..38.139) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
455 accept X.X..38.127 (X.X..38.127) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
444 accept X.X.6.108 (X.X.6.108) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
435 accept X.X.40.56 (adasdass.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0

Last 24 Hours Top 25 Firewall Acceppted connetions ordered by Src_IP

Count action src_ip dst_port dst_ip messages
3057 accept X.X..18.201 (X.X..18.201) [] [i] 0 X.X.254.13 (X.X.254.13) [] [i] 0
2773 accept X.X.40.41 (X.X.40.41) [] [i] smtp X.X..6.64 (X.X..6.64) [] [i] 0
2472 accept X.X.40.40 (X.X.40.40) [] [i] http 63.71.8.41 (prod-www.asdasdas.com) [] [i] 0
2436 accept X.X.40.42 (X.X.40.42) [] [i] smtp X.X..6.64 (X.X..6.64) [] [i] 0
2210 accept X.X..6.51 (whatsup.somecompany.com) [] [i] 0 X.X.40.51 (wadasdas01.somecompany.com) [] [i] 0
1782 accept X.X.30.7 (X.X.30.7) [] [i] smtp X.X..32.44 (asdaDJAh2.somecompany.com) [] [i] 0
1591 accept X.X..16.208 (00034728c3e4.somecompany.com) [] [i] 0 129.105.253.9 (lev-mdf-7-ser-2-1.northwestern.edu) [] [i] 0
1509 accept 192.168.194.108 (192.168.194.108) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
1255 accept X.X.40.31 (adasdaspf02.somecompany.com) [] [i] MS-SQL-Server X.X..32.52 (sql2kadasdasdata.somecompany.com) [] [i] 0
1176 accept X.X..7.88 (r1603-pc-6-dl1.somecompany.com) [] [i] smtp 66.33.213.158 (a1.postal.mail.dreamhost.com) [] [i] 0
1088 accept X.X.40.30 (adasdaspf01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
912 accept X.X..18.77 (somecompanysim.somecompany.com) [] [i] 0 X.X.40.56 (adasdass.somecompany.com) [] [i] 0
894 accept X.X..37.124 (adasdas518.somecompany.com) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
891 accept X.X..2.10 (X.X..2.10) [] [i] 8585 192.168.204.30 (192.168.204.30) [] [i] 0
727 accept 10.19.1.2 (w2k-hpov-01.testadasdas.somecompany.com) [] [i] snmp-read X.X..254.13 (somecompany-perimeter2.testadasdas.somecompany.com) [] [i] 0
655 accept X.X..6.10 (X.X..6.10) [] [i] 0 X.X21.226 (riveram.lab.somecompany.com) [] [i] 0
633 accept X.X.52.32 (hph-mfxp-01.somecompany.com) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
570 accept 67.38.111.245 (adsl-67-38-111-245.dsl.chcgil.ameritech.net) [] [i] smtp x.x.x.135 (x.x.x.135) [] [i] 0
543 accept X.X..38.59 (X.X..38.59) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
541 accept X.X..38.51 (X.X..38.51) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
530 accept X.X.3.51 (X.X.3.51) [] [i] http 199.230.128.100 (vwww.cardinal.com) [] [i] 0
510 accept X.X.40.20 (adasdas01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
506 accept X.X.30.100 (adasdas100.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
487 accept X.X.40.21 (adasdas02.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
477 accept X.X.30.200 (somecompanypathadasdas.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
459 accept X.X.40.45 (adasdasadasdas01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
456 accept X.X.40.46 (adasdasadasdas02.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
455 accept X.X..38.127 (X.X..38.127) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
455 accept X.X..38.139 (X.X..38.139) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
444 accept X.X.6.108 (X.X.6.108) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
434 accept X.X.40.56 (adasdass.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
429 accept X.X.30.29 (somecompanyftp01.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
428 accept X.X.40.60 (somecompanysurvey.somecompany.com) [] [i] TCP_5005 X.X..7.63 (X.X..7.63) [] [i] 0
416 accept X.X..96.157 (X.X..96.157) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
409 accept X.X..7.121 (adasdas901.somecompany.com) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
407 accept X.X.40.51 (wadasdas01.somecompany.com) [] [i] TCP_5031 X.X..6.29 (X.X..6.29) [] [i] 0
394 accept X.X..14.56 (X.X..14.56) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
347 accept X.X.2.90 (r1603-pc-3-ac.somecompany.com) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0
344 accept X.X..16.85 (krisxp01.somecompany.com) [] [i] http 216.109.119.252 (p1.cpn.vip.dcn.yahoo.com) [] [i] 0
343 accept X.X..38.138 (X.X..38.138) [] [i] http 205.205.16.182 (205.205.16.182) [] [i] 0

Last 24 Hours Top 25 Firewall Dropped connetions ordered by Src_IP

Count action src_ip dst_port dst_ip messages
1804 drop X.X..6.10 (X.X..6.10) [] [i] 0 X.X24.226 (X.X24.226) [] [i] Local interface address spoofing
891 drop X.X..2.10 (X.X..2.10) [] [i] 8585 192.168.204.30 (192.168.204.30) [] [i] Local interface address spoofing
750 drop 65.103.130.128 (65-103-130-128.spkn.qwest.net) [] [i] rpc_135 X.X17.8 (im.testadasdas.somecompany.com) [] [i] 0
547 drop 204.153.216.45 (204.153.216.45) [] [i] 0 X.X19.202 (X.X19.202) [] [i] 0
470 drop 24.36.39.101 (d36-39-101.home1.cgocable.net) [] [i] https X.X17.8 (im.testadasdas.somecompany.com) [] [i] 0
347 drop X.X.30.39 (X.X.30.39) [] [i] 49147 129.105.16.57 (merle.it.northwestern.edu) [] [i] 0
346 drop 194.102.250.101 (helvespid1.kappa.ro) [] [i] 15118 X.X30.146 (X.X30.146) [] [i] 0
287 drop X.X..2.19 (adasdas.testadasdas.somecompany.com) [] [i] 0 192.168.193.42 (p-830-prt-500-a.testadasdas.somecompany.com) [] [i] 0
270 drop 69.225.28.128 (adsl-69-225-28-128.dsl.skt2ca.pacbell.net) [] [i] 15118 X.X19.219 (X.X19.219) [] [i] 0
260 drop X.X..12.35 (dmsexp001.inw.com) [] [i] 1238 192.168.0.12 (192.168.0.12) [] [i] Local interface address spoofing
224 drop X.X..16.208 (00034728c3e4.somecompany.com) [] [i] 0 192.168.193.1 (192.168.193.1) [] [i] Local interface address spoofing
178 drop X.X..64.65 (X.X..64.65) [] [i] Spybot-Virus-Control-Conenctio 207.150.160.37 (unknown.sagonet.net) [] [i] 0
136 drop 64.118.229.78 (adsl-64-118-229-78.netrox.net) [] [i] microsoft-ds X.X21.103 (salasm.matfetmed.somecompany.com) [] [i] 0
129 drop X.X..9.216 (nimmstl.testadasdas.somecompany.com) [] [i] 0 192.168.2X.X.4 (192.168.2X.X.4) [] [i] 0
121 drop X.X..34.31 (X.X..34.31) [] [i] 20100 192.168.0.2 (192.168.0.2) [] [i] Local interface address spoofing
101 drop 61.235.154.101 (61.235.154.101) [] [i] 1026 X.X19.14 (X.X19.14) [] [i] 0
90 drop 24.39.174.5 (fafnir.cbord.com) [] [i] smtp x.x.x.136 (x.x.x.136) [] [i] 0
88 drop 200.204.121.248 (200-204-121-248.speedyterra.com.br) [] [i] nbadasdas X.X21.167 (mats07.lab.somecompany.com) [] [i] 0
87 drop X.X..18.80 (somecompany-d764b6743c3.somecompany.com) [] [i] telnet 10.154.1.2 (10.154.1.2) [] [i] 0
86 drop X.X..254.13 (somecompany-perimeter2.testadasdas.somecompany.com) [] [i] 3462 X.X..18.200 (X.X..18.200) [] [i] Server side packet of an old UDP connection
76 drop X.X..32.19 (1301-ds-123-c.somecompany.com) [] [i] domain-udp 192.175.48.1 (prisoner.iana.org) [] [i] 0
71 drop X.X..2.21 (adasdas.testadasdas.somecompany.com) [] [i] 4857 32.90.22.11 (32.90.22.11) [] [i] 0
68 drop 62.84.140.11 (ph700-1c54-dial009.sbone.cz) [] [i] 15118 X.X30.234 (X.X30.234) [] [i] 0
58 drop X.X84.195 (X.X84.195) [] [i] microsoft-ds X.X19.2 (X.X19.2) [] [i] 0
47 drop X.X..4.101 (adasdas.somecompany.com) [] [i] 0 216.34.170.164 (216.34.170.164) [] [i] 0
46 drop 206.81.53.58 (ip206-81-53-58.z53-81-206.customer.algx.net) [] [i] 444 X.X21.54 (mgoe01.med-grp.somecompany.com) [] [i] 0
45 drop 63.71.10.25 (63.71.10.25) [] [i] 0 x.x.x.156 (x.x.x.156) [] [i] 0
43 drop 198.173.26.217 (198.173.26.217) [] [i] microsoft-ds x.x.x.141 (x.x.x.141) [] [i] 0
43 drop X.X..2.17 (mycprl.testadasdas.somecompany.com) [] [i] 0 32.90.22.11 (32.90.22.11) [] [i] 0
42 drop X.X..4.40 (adasdas.somecompany.com) [] [i] 0 6.1.3.26 (6.1.3.26) [] [i] 0
41 drop X.X..6.99 (X.X..6.99) [] [i] 631 192.168.204.73 (192.168.204.73) [] [i] Local interface address spoofing
37 drop 210.101.95.50 (210.101.95.50) [] [i] MS-SQL-Server X.X19.9 (X.X19.9) [] [i] 0
37 drop X.X..32.37 (1301-ps-123-c.somecompany.com) [] [i] snmp-read 192.168.193.42 (p-830-prt-500-a.testadasdas.somecompany.com) [] [i] 0
36 drop 64.2.157.10 (64.2.157.10.ptr.us.xo.net) [] [i] 26421 x.x.x.156 (x.x.x.156) [] [i] 0
36 drop X.X..20.109 (X.X..20.109) [] [i] imap 216.152.251.170 (server9.vnpages.net) [] [i] 0
31 drop X.X..16.237 (r1301-pc-133-a.somecompany.com) [] [i] snmp-read 192.168.193.42 (p-830-prt-500-a.testadasdas.somecompany.com) [] [i] 0
30 drop X.X..8.121 (r1001-lt-348-a.somecompany.com) [] [i] domain-udp 12.127.16.77 (12.127.16.77) [] [i] 0
27 drop 218.75.91.253 (218.75.91.253) [] [i] 32039 X.X21.61 (holtl.obgyn.somecompany.com) [] [i] 0
27 drop 61.153.207.30 (61.153.207.30) [] [i] 19774 X.X30.43 (X.X30.43) [] [i] 0
26 drop 61.159.15.2 (61.159.15.2) [] [i] MSSQL_resolver X.X21.239 (p-evan-prt-5242-a.testadasdas.somecompany.com) [] [i] 0

Last 24 Hours Top 25 Firewall Rejected connetions ordered by Src_IP

Count action src_ip dst_port dst_ip messages
9034 reject X.X..24.83 (X.X..24.83) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
2286 reject X.X.4.109 (r1603-pc-5th-cd.somecompany.com) [] [i] http 209.202.141.212 (consumerinput.com) [] [i] 0
792 reject X.X..20.177 (X.X..20.177) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
718 reject X.X..4.110 (X.X..4.110) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
668 reject X.X..30.85 (X.X..30.85) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
418 reject 10.140.2.123 (r9977-pc-admn-b.somecompany.com) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
285 reject X.X..4.96 (X.X..4.96) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
131 reject X.X.18.168 (X.X.18.168) [] [i] http 170.224.224.135 (proxycfg.or4.marketscore.com) [] [i] 0
128 reject X.X.20.61 (X.X.20.61) [] [i] http 170.224.224.135 (proxycfg.or4.marketscore.com) [] [i] 0
122 reject X.X..8.16 (X.X..8.16) [] [i] http 134.217.3.38 (svfulaxeda.beckman.com) [] [i] 0
99 reject X.X..8.18 (X.X..8.18) [] [i] http 206.24.222.123 (206.24.222.123) [] [i] 0
96 reject X.X..70.124 (X.X..70.124) [] [i] http 129.250.226.26 (mm.delfinproject.com) [] [i] 0
94 reject X.X.8.139 (r1603-pc-cc8-e.somecompany.com) [] [i] http 66.179.234.173 (66.179.234.173) [] [i] 0
91 reject 10.130.8.251 (glen-pc-b051-a.somecompany.com) [] [i] http 129.250.226.26 (mm.delfinproject.com) [] [i] 0
75 reject X.X..92.55 (X.X..92.55) [] [i] http 216.21.215.22 (adk215-22.adknowledge.com) [] [i] 0
70 reject X.X..4.79 (X.X..4.79) [] [i] http 216.148.246.135 (proxycfg.sj4.marketscore.com) [] [i] 0
68 reject 10.140.4.79 (10.140.4.79) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
64 reject X.X..16.116 (X.X..16.116) [] [i] http 170.224.224.135 (proxycfg.or4.marketscore.com) [] [i] 0
63 reject X.X..58.69 (X.X..58.69) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
56 reject X.X..96.63 (X.X..96.63) [] [i] http 170.224.224.71 (proxycfg.or2.marketscore.com) [] [i] 0
56 reject X.X..8.170 (X.X..8.170) [] [i] http 170.224.224.135 (proxycfg.or4.marketscore.com) [] [i] 0
55 reject X.X..8.89 (r1001-pc-318-g.somecompany.com) [] [i] http 170.224.224.135 (proxycfg.or4.marketscore.com) [] [i] 0
55 reject X.X..20.112 (X.X..20.112) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
50 reject X.X.7.83 (mmoody) [] [i] http 216.23.176.101 (216.23.176.101) [] [i] 0
49 reject X.X..8.139 (X.X..8.139) [] [i] http 170.224.224.103 (proxycfg.or3.marketscore.com) [] [i] 0
49 reject X.X..6.100 (X.X..6.100) [] [i] http 216.152.240.11 (216.152.240.11) [] [i] 0
48 reject X.X.16.84 (X.X.16.84) [] [i] http 170.224.224.135 (proxycfg.or4.marketscore.com) [] [i] 0
38 reject X.X.12.62 (X.X.12.62) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
38 reject X.X..44.95 (X.X..44.95) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
38 reject X.X.30.52 (X.X.30.52) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
38 reject X.X..4.72 (X.X..4.72) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
38 reject X.X..44.52 (X.X..44.52) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
36 reject X.X.24.76 (X.X.24.76) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
34 reject X.X..8.54 (r1001-pc-306-b.somecompany.com) [] [i] http 204.0.143.202 (204.0.143.202) [] [i] 0
34 reject X.X.30.69 (X.X.30.69) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
30 reject X.X..65.93 (X.X..65.93) [] [i] http 63.240.63.69 (campaign.dataviz.com) [] [i] 0
30 reject X.X.20.43 (X.X.20.43) [] [i] http 209.133.111.5 (209.133.111.5.available.above.net) [] [i] 0
30 reject X.X..46.112 (X.X..46.112) [] [i] http 64.94.137.51 (ads.180solutions.com) [] [i] 0
28 reject X.X.5.204 (X.X.5.204) [] [i] http 216.23.176.100 (216.23.176.100) [] [i] 0
25 reject X.X..32.61 (X.X..32.61) [] [i] http 81.3.71.65 (81.3.71.65) [] [i] 0