Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Audit Firewall By Port Number & OS Logging

    Firewalling
    3
    3
    314
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tleary
      last edited by

      Does anyone have a service, application, or script they use that can correlate an blocked attempt at your filewall with processes running on your computer at the same time?

      context: I auditing Windows with forensics tools. I see one blocked attempt from Latin America on my LAN. I am wondering what it was trying to go to on my computer. I am hoping by using a logging tool on the operating system to can find the matching port at that time.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Perhaps pfBlocker with OpenID running on LAN?  Post a screen of that block so we can see what's going on.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          "I see one blocked attempt from Latin America on my LAN"
          "I am wondering what it was trying to go to on my computer."

          You mean what on your computer was trying to go there?  What port was it - could of just been an add in a website pointing to some server hosted there..

          You could use a simple tool like tcpview from MS to see where your applications are going for tcp.. But going to have to really catch it in real time… Not like you can go back days later and see what tried to make a network connection days ago, etc.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.