[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

tcpspy log interpretation



The below log entries are from tcpspy in syslog. What do they mean? they are from the firewall which is running a transparent squid proxy and iptables.

noone inside the firewall could have hit those external IPs for any reason.

thanks

Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1167, remote 24.94.162.89:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1169, remote 24.94.162.97:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1167, remote 24.94.162.89:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1169, remote 24.94.162.97:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1170, remote 24.94.162.89:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1168, remote 24.94.162.88:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1170, remote 24.94.162.89:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
	65.30.34.80:1168, remote 24.94.162.88:www



Reply to: