This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Logs

Does anyone know if I can pull or find the full NAT translation from the UTM?  The firewall log only seems to have the Firewall's IP and the destination.  But that doesn't help me find the Internal IP that was using that port to go to that IP Address.


2013:09:07-15:31:22 Client-1 ulogd[4568]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="0:22:2d:92:a[:D]7" dstmac="0:1a:8c:32:67[:D]9" srcip="204.83.171.40" dstip="67.78.195.194" proto="6" length="40" tos="0x00" prec="0x20" ttl="106" srcport="3389" dstport="1425" tcpflags="RST"


This thread was automatically locked due to age.
Parents
  • You're right, thanks, Barry.  I was going too fast.  If there's no complaint from the users about interrupted RDP sessions, then it's nothing to worry about.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • You're right, thanks, Barry.  I was going too fast.  If there's no complaint from the users about interrupted RDP sessions, then it's nothing to worry about.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data