I've been doing a network security revamp and have newb issues. Hopefully I can solicit some insight from the guys who know hardware and networks really well
I'm running 2 XP machines behind a newer linksys soho fw, and an ethernet drive. also mcafee software fw and virus and netscape (instead of IE) on everything.
In the linksys log, any time I hit a website I see several outgoing connections to various ip's. Furthermore, it looks like the ports in the log occur sequentially which seems suspect to me (1564-1571 below etc). Is this normal?
For example, below are the log entries from one hit to the elitetrader.com main page. It looks like outgoing traffic went to 5 different destinations. What could these be, things like Avenue A, etc, or is this normal?
New NAPT Log
2006-06-21 22:38:22 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1564->208.234.169.12:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1565->208.234.169.12:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1566->208.234.169.12:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1567->208.234.169.72:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1568->65.205.8.182:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1569->208.234.169.72:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1570->216.73.87.187:80 [Forward]
2006-06-21 22:38:24 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1571->202.89.44.141:80 [Forward]
I'm running 2 XP machines behind a newer linksys soho fw, and an ethernet drive. also mcafee software fw and virus and netscape (instead of IE) on everything.
In the linksys log, any time I hit a website I see several outgoing connections to various ip's. Furthermore, it looks like the ports in the log occur sequentially which seems suspect to me (1564-1571 below etc). Is this normal?
For example, below are the log entries from one hit to the elitetrader.com main page. It looks like outgoing traffic went to 5 different destinations. What could these be, things like Avenue A, etc, or is this normal?
New NAPT Log
2006-06-21 22:38:22 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1564->208.234.169.12:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1565->208.234.169.12:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1566->208.234.169.12:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1567->208.234.169.72:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1568->65.205.8.182:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1569->208.234.169.72:80 [Forward]
2006-06-21 22:38:23 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1570->216.73.87.187:80 [Forward]
2006-06-21 22:38:24 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.1.100:1571->202.89.44.141:80 [Forward]
