larrypg

firewall logs

Recommended Posts

Hello,

I am curious as to why when I click show firewall log it usually shows very little. About the only thing that shows up are hits to port 1433 and my dns server not being able to connect to. In Linux my logs show many many hits. Not a big deal but curious.

Thanks,

Larry

Share this post


Link to post
Share on other sites

larrypg,

I guess only the Blocked events are logged.

If you choose to log Allowed events or All activity the log would most likely show more information.

Share this post


Link to post
Share on other sites

Thank you for the response. As far as I know the options are to show allowed, blocked, or all. I only want to see blocked events but am wondering why so little shows up.

Just as an example...It looks like the log reset itself and in the four hours since there has only been two blocked events showing up...both from port 6000 to port 1433.

In this same time period in Linux it would show many different attempts to many different ports from many different ips. Probably sixty attempts versus the two that show up in the Online Armor logs.

By the way...if I am scanned from some place that I go to and request the scan (grc.com) it does show up.

Well like I said it is not really that important but would still like to try and understand why the difference.

Share this post


Link to post
Share on other sites

Larry,

I don't use Linux, can't compare results here. Also i'm unable to connect to the internet without my router. GRC ShieldsUp! shows 100% stealth for my system. Nothing shows up in OA's firewall log as blocked.

Share this post


Link to post
Share on other sites

Hello again...it has been a few days so thought I would check if anyone else has any ideas. OA is still only showing very very minimal activity blocked. As said previously 90% (sometimes 100%) of the info is only from port 6000 to port 1433 and this is only being listed a few times a day.

Share this post


Link to post
Share on other sites

You can see a more detailed version of the Firewall log by looking in the Program Files\Online Armor\Logs folder. It will still show the same number of blocked events as the Firewall log window displays though. Considering that you've said the GRC port scan records blocked events (and presumably since it does, you are not behind a router that's blocking it first), OA is operating as it should do. OA also stealths ports by default so unless you have numerous ports intentionally left open by allowing inbound connections to them in OA, you wouldn't be an obvious target for port scans.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.