Received From: ecs-3->/var/log/messages
Rule: 4151 fired (level 10) -> "Multiple Firewall drop events from same source."
Portion of the log(s):
Code: Select all
May 12 17:08:52 ecs-3 kernel: DROP_ASL_TORTIX IN=em1 OUT= MAC=78:2b:cb:1b:2b:02:00:22:19:1d:fb:94:08:00 SRC=XX.186.XXX.71 DST=10.XXX.XXX.173 LEN=52 TOS=0x00 PREC=0x00 TTL=114 ID=25965 DF PROTO=TCP SPT=13077 DPT=30000 SEQ=4273183466 ACK=0 WINDOW=8192 RES=0x00 SYN URGP=0 OPT (020405B40103030201010402)