Re: How to tell if a firewall alert is suspicious or not

From: Gerard Schroeder (Gshroeder22031_at_hotmail.com)
Date: 09/15/05


Date: Thu, 15 Sep 2005 13:04:34 GMT

On Thu, 15 Sep 2005 07:56:07 -0400, Karl Levinson, mvp wrote:

> There are ways you can research these things... however, you will get so
> many of these alerts, and it is so fruitless to research them all
...
> you should look up what the remote IP address is
> www.nwtools.com or www.netsol.com
...
> A really smart firewall would let you inspect the TCP flags and contents of
> the incoming packet

I thank you for your detailed suggestions summarized below as:
1. There exists innocent common connections reported by the firewall
2. We can find the NAME of the IP address contacting us for clues
3. The content of the incoming packet may contain clues

Regarding the first interesting comment above:
- Is there a site where all the common innocent connections are listed?
- I searched (before I posted) and did not find one (but it may exist).
- If not, I don't mind starting a list (in this post perhaps?).

Regarding looking up the NAME of the IP address:
- WHY would my DNS provider suddently connect (this does not happen often)?
- I keep a list of the common contact requests & this isn't one of them.
- I said NO to the request & I don't see negative consequences.

Regarding the content of the incoming packets:
- Sygate Personal Firewall 5.6 provides a Yes/No/Details response
- The DETAILS button gives more information (cryptic to me, a novice).
- Again I wonder if there is a list of known non-dangerous contacts.

For we novices who still desire basic firewall protection, it would be nice
to refer to a list of known generally non-dangerous requests to accept.
I'll post separately (as it's slightly OT) the list I maintain of what I
THINK are innocent requests (but I'm not sure) that I get every day so as
to START this desired list (if it doesn't exist already).

The particular message I posted from my DNS server does NOT happen often so
that is what startled me.