F-SECURE ANTI-VIRUS FOR MICROSOFT EXCHANGE 8.00 - Administrator's Manual - page 238
238
Receiving connection
If the application has opened a LISTEN connection it is acting as an
server and remote computers can connect to the port which the
connection was opened for. Action log records these also these
connections.
The fields are:
Dynamic rule entry
If an application opens a listening connection and the user allows it,
then the static firewall rules might prevent that connection. Therefore
a dynamic rule is used to allow this connection inbound, just for the
time of connection, for this applications use only.
The fields are:
1
2
3
4
5
6
7
8
9
10
07/15/03
16:48:00
info
appl control
unknown
allow
receive
17
10.128.129.146
138
1. Date
2. Time
3. Type
4. Internal Reason
5. Name of application
6. Application control action
7. Network action
8. Protocol
9. Remote ip
10. Remote port
1
2
3
4
5
6
7
8
9
10
11
12
07/15/03
16:47:59
info
dynamic rule
added
0.0.0.0
255.255.255.0
0
65535
371
371
allow
07/15/32
16:48:23
info
dynamic rule
removed
0.0.0.0
255.255.255.0
0
65535
371
371
allow
1. Date
2. Time
3. Alert type
4. Rule type
5. Action taken
6. Remote IP range IP
7. Remote IP range
netmask
8. Remote port range from
9. Remote port range to
10. Local port from
11. Local port to
12. Rule action (allow/
deny)