The below log entries are from tcpspy in syslog. What do they mean? they are from the firewall which is running a transparent squid proxy and iptables.

noone inside the firewall could have hit those external IPs for any reason.

thanks

Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1167, remote 24.94.162.89:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1169, remote 24.94.162.97:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1167, remote 24.94.162.89:www
Jul 26 17:02:15 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1169, remote 24.94.162.97:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1170, remote 24.94.162.89:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1168, remote 24.94.162.88:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1170, remote 24.94.162.89:www
Jul 26 17:02:16 portal tcpspy[330]: disconnect: user proxy, local
        65.30.34.80:1168, remote 24.94.162.88:www

Reply via email to