[logs] cisco pix traffic direction

From: saravanakumar (saravanakumar@private)
Date: Mon Sep 19 2005 - 23:45:16 PDT

Dear All,

I have the following logs from Cisco PIX.

<166>Aug 10 2005 13:33:39 pix: %PIX-6-302013: Built outbound TCP 
connection 31174127 for outside: ( 
to inside: (

<166>Aug 10 2005 13:33:39 saravana: %PIX-6-302014: Teardown TCP 
connection 31174127 for outside: to 
inside: duration 0:00:39 bytes 3549 TCP FINs

One is transaction start log and other one is transaction finish log.  
Using the above two logs, how can I identify how many bytes coming into 
your LAN and how many bytes going out of my firewall?

CiscoPIX has only one bytes field which gives you the data transferred. 
I want to identify incoming bytes and outgoing bytes. Or at least can I 
conclude that if originator of the traffic is behind the firewall, all 
the traffic is INBOUND.

LogAnalysis mailing list

This archive was generated by hypermail 2.1.3 : Tue Sep 20 2005 - 06:30:54 PDT