This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Packet Filter Logging Question

All-

I need some advice regarding packet filter logging. It seems that when content is delivered from Akami Technologies their servers leave a large number of logs usually ending with tcpflag RST. Please see example enclosed. My question is how do I prevent this needless logging? Mods I may have placed my post in an incorrecty under network security in place of management, logging.... Please relocate if necessary.

Thanks,
Jim

2011:05:05-12:44:14 OASIS ulogd[5189]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="0:90:1a:a1:41:27" dstmac="0:24:7e:x:y:z" srcip="69.31.28.242" dstip="173.A.B.76" proto="6" length="40" tos="0x00" prec="0x00" ttl="253" srcport="443" dstport="3097" tcpflags="RST" 
2011:05:05-12:44:14 OASIS ulogd[5189]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="0:90:1a:a1:41:27" dstmac="0:24:7e:x:y:z" srcip="69.31.28.232" dstip="173.A.B.76" proto="6" length="40" tos="0x00" prec="0x00" ttl="253" srcport="443" dstport="3119" tcpflags="RST" 
[:S]


This thread was automatically locked due to age.
Parents
  • Guys,

    Thanks for your help. You my be correct that the rule is not correctly configured. Currently it is configured as Source Any> Service Web Surfing> Destination> External Wan Address > Drop.  Possibly I should configure it as Source Any> Service Web Surfing> Network Group containing CIDR's OF Akami Servers> Drop? Is it possible to use create a DNS group in place of the network group using http://*.deploy.akamaitechnologies.com?

    Regards,
    Jim
Reply
  • Guys,

    Thanks for your help. You my be correct that the rule is not correctly configured. Currently it is configured as Source Any> Service Web Surfing> Destination> External Wan Address > Drop.  Possibly I should configure it as Source Any> Service Web Surfing> Network Group containing CIDR's OF Akami Servers> Drop? Is it possible to use create a DNS group in place of the network group using http://*.deploy.akamaitechnologies.com?

    Regards,
    Jim
Children
No Data