[fw-wiz] Log checking?

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 09/28/04

  • Next message: Desai, Ashish: "RE: [fw-wiz] Log checking?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 28 Sep 2004 16:05:24 -0400 (EDT)
    
    

    Back when I had real production firewalls, I'd log all the permitted
    traffic for a while, then do some analysis of the data to get a
    feel for things like tunnels, misbehaving users, etc.

    I've always felt that worrying about denied traffic was mostly for sport-
    if the firewall's policy blocked it, I wasn't all that worried about much
    more than overall trends- what got *through* the firewall seemed to be the
    more interesting set of things.

    I'm just wondering if the subset of folks who actually look at their
    firewalls mostly looks at denied traffic only, or if it's a common
    practice to look at the permitted stuff too? If so, what sorts of things
    are you using, and are you finding anything interesting?

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Desai, Ashish: "RE: [fw-wiz] Log checking?"

    Relevant Pages

    • Re: browstat wont run
      ... >>>First I just extracted it to my desktop for easy access, ... >> Paul, ... >Windows firewalls and tried to connect, so I am guessing it is not the ... OK, looking at browstat: ...
      (microsoft.public.windowsxp.network_web)
    • Re: [fw-wiz] iso 17799
      ... On Thu, 22 Jul 2004, Paul D. Robertson wrote: ... Ok, in the "You get what you ask for category," the Internet Firewalls FAQ ... Definitely on the list are a section on personal firewalls, ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Maximum number of subnets on a firewall
      ... > try to attach it to any available product: I was asked to plan a network for ... > companies I've concluded that all of them together will need 10 subnets ... firewalls. ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)
    • RE: IPS (was: [fw-wiz] Sources for Extranet Designs?)
      ... Now that we've actually gotten back to the point where firewalls are ... The only thing something like network IPS gets you over a tradtional ... than proactive security? ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)
    • Re: [fw-wiz] iso 17799
      ... Neither the new editions of Firewalls and Internet Security, ... Building Internet Firewalls have this list mentioned in them, ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)