The below log entries are from tcpspy in syslog. What do they mean?
they are from the firewall which is running a transparent squid proxy
and iptables.
noone inside the firewall could have hit those external IPs for any reason.
thanks
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1167, remote 24.94.162.89:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1169, remote 24.94.162.97:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1167, remote 24.94.162.89:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1169, remote 24.94.162.97:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1170, remote 24.94.162.89:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1168, remote 24.94.162.88:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1170, remote 24.94.162.89:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
65.30.34.80:1168, remote 24.94.162.88:www