ASL 6.004
My log shows dropped packets with a destination port of 445, but I'm dropping Microsoft-SMB (static definition) without logging, and this rule is near the top. I don't understand why this traffic is being logged. I created the rule so I don't have to see this crap in my log files.
I see many entries from various ip addresses, but here's what a sample log entry looks like:
13:06:38 24.86.30.122 2226 -> 445 TCP 48 118 CE DF SEQ=855761206 ACK=0 WINDOW=64240 SYN URGP=0
Here's what my Rules look like:
http://www.reedkey.com/image/rules.JPG
Any advice? Is this a bug?
Dan
This thread was automatically locked due to age.