NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Odd Logging Question


  • To: [email protected]
  • Subject: Re: [FW-1] Odd Logging Question
  • From: "Roelandts, Guy" <[email protected]>
  • Date: Thu, 14 Feb 2002 10:47:53 +0100
  • Reply-to: Mailing list for discussion of Firewall-1 <[email protected]>
  • Sender: Mailing list for discussion of Firewall-1 <[email protected]>
  • Thread-index: AcG01YgRLnjwXm3AS4i0kV0SqS2piQAZuD5g
  • Thread-topic: [FW-1] Odd Logging Question

Steve,

   To comment on Scott answer.

   Whatever version you are running, it seems Check Point first looks for the name of
 a service in the services files (being /etc or \winnt\system32\drivers\etc) then in
 its own service file. Several services show this behavior, SMTP, DOMAIN-UDP/TCP ...

Met vriendelijke groeten - Bien à vous - Kind regards
Guy ROELANDTS
EMEA GS Internet Expertise Centre - CCSA & CCSE
Compaq Software Engineer - Belgium
E-mail : [email protected]
Tel: +32(02)729.77.44 (options 3 - 3 - 1)
Fax: +32(02)729.77.65
==========================================================
This message may contain confidential and/or proprietary information,
and is intended only for the person/entity to whom it was originally
addressed. The content of this message may contain private views and
opinions which do not constitute a formal disclosure or commitment
unless specifically stated. Should you receive this message by mistake
please inform the sender immediately.
==========================================================


-----Original Message-----
From: Steve [mailto:[email protected]]
Sent: 13 February 2002 21:56
To: [email protected]
Subject: [FW-1] Odd Logging Question


One of our remote office was having mail problems. This was blamed on
routing changes which were then backed out. However inspecting the Firewall
logs before and after the routing backout I notice a difference in the
logging on Firewall-1.

Before (port 25) email was logged as "mail" in the firewall logs, but the
following day it was logged as "smtp", which is leading me to believe a
change in the Firewall which no one is telling us about. Do different
versions or patches of Firewall-1 log port 25 traffic as different in the
log file?

Cheers,

-Steve

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.