I've seen some crazy odd traffic being reported by the ASG box as IRC traffic, but I have IRC clients blocked and none running on the machine in question as the source. Not sure what to make of it. I have scanned for viruses and spyware and found nothing. There are days and days of dropped lines in the log files between the same two addresses.
The dstip is a web server.
The srcip is one of my computers.
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:42:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1577" dstport="30235" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:42:57 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1581" dstport="45955" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:44:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1585" dstport="42568" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:44:27 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1589" dstport="43839" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:45:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1593" dstport="45973" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:45:57 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1597" dstport="34016" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:47:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1601" dstport="33410" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:47:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1605" dstport="40146" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:48:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1609" dstport="39734" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:48:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1613" dstport="48088" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:50:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1617" dstport="37128" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:50:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1621" dstport="33875" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:51:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1625" dstport="42650" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:51:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1629" dstport="34460" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:53:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1633" dstport="44023" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:53:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1637" dstport="40826" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:54:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1641" dstport="30520" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:54:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1645" dstport="39976" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:56:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1649" dstport="42274" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:56:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1653" dstport="48404" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:57:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1657" dstport="42959" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:57:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1661" dstport="49305" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:59:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1665" dstport="48912" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:59:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1669" dstport="30449" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-04:00:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1673" dstport="31752" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-04:00:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1677" dstport="48992" tcpflags="ACK"
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-04:02:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1681" dstport="44489" tcpflags="ACK"
Am I reading this correctly? Is this showing an IRC connection going out from a local computer?
This thread was automatically locked due to age.