Firewall messages

Hi All,
I'm really new to firewalls, I have configured one using CCP and the basic firewall wizard with medium security. I just have my laptop plugged into the LAN port and I noticed a couple weird logs that I want to ask about when surfing the web, and retrieving outlook emails.
I'm getting 4 main messages:
004528: Jul  6 11:26:46.528 MDT: %APPFW-4-HTTP_DEOBFUSCATION: Deobfuscation signature (15) detected - session 192.168.0.2:64657 74.125.225.121:80 on zone-pair ccp-zp-in-out class ccp-protocol-http appl-class ccp-http-blockparam
004620: Jul  6 11:30:21.596 MDT: %APPFW-4-HTTP_DEOBFUSCATION: Deobfuscation signature (16) detected - session 192.168.0.2:64640 74.125.225.121:80 on zone-pair ccp-zp-in-out class ccp-protocol-http appl-class ccp-http-blockparam
004603: Jul  6 11:27:08.164 MDT: %APPFW-4-HTTP_PROTOCOL_VIOLATION: HTTP protocol violation (0) detected - session 208.38.45.167:80 192.168.0.2:64852 on zone-pair ccp-zp-in-out class ccp-protocol-http appl-class ccp-http-blockparam
When using Send/Receive in Outlook i get:
004630: Jul  6 11:33:39.980 MDT: %FW-5-POP3_INVALID_COMMAND: (target:class)-(ccp-zp-in-out:ccp-protocol-pop3):Invalid POP3 command from initiator (192.168.0.2:64993): Invalid verb
Everything seems to work fine, I can send and receive emails, I can surf websites and google with no issues. Is this just logging or should I be worried about any of these messages?
Thanks!!!
-Chris
More Info
#show policy-map type inspect http
  Policy Map type inspect http ccp-action-app-http
    Class ccp-http-blockparam
      Log
      Allow
    Class ccp-app-httpmethods
      Log
      Reset
    Class ccp-http-allowparam
      Log
      Allow
#show class-map type inspect http
Class Map type inspect http match-any ccp-app-httpmethods (id 8)
   Match  request method bcopy
   Match  request method bdelete
   Match  request method bmove
   Match  request method bpropfind
   Match  request method bproppatch
   Match  request method connect
   Match  request method copy
   Match  request method delete
   Match  request method edit
   Match  request method getattribute
   Match  request method getattributenames
   Match  request method getproperties
   Match  request method index
   Match  request method lock
   Match  request method mkcol
   Match  request method mkdir
   Match  request method move
   Match  request method notify
   Match  request method options
   Match  request method poll
   Match  request method propfind
   Match  request method proppatch
   Match  request method put
   Match  request method revadd
   Match  request method revlabel
   Match  request method revlog
   Match  request method revnum
   Match  request method save
   Match  request method search
   Match  request method setattribute
   Match  request method startrev
   Match  request method stoprev
   Match  request method subscribe
   Match  request method trace
   Match  request method unedit
   Match  request method unlock
   Match  request method unsubscribe
Class Map type inspect http match-any ccp-http-blockparam (id 15)
   Match  request port-misuse im
   Match  request port-misuse p2p
   Match  req-resp protocol-violation
Class Map type inspect http match-any ccp-http-allowparam (id 4)
   Match  request port-misuse tunneling

WAMP!
Hi Chris, Mike here. I see the problem there. We have a section ask the expert where Julio Carvajal is answering Firewalling questions in IOS devices.
Going back to the question, I see where the problem is. Many Websites on the internet are not HTTP compliant, what you are doing with the configuration you did with CCP is creating this AGGRESSIVE inspection in layer 7 inspection for web traffic, meaning, the traffic on HTTP may slow down or have Random connectivity issues. This is mainly because of the service policy configured inside of the HTTP inspection.
As I can see is not only HTTP but it is extending to other protocols as well, my best advice for you is, if you are sure where attack may come from, apply a deep packet inspection to it. I dont particularly like wizzards so if you wanna get deep to a protocol it would be better if you know what you want to match.
Leave the protocols without layer 7 inspection, they will still look at the form of the packet and make sure it is RFC compliant, custom commands (POP and SMTP) custom Methods (HTTP) may get dropped as you can see.
Hope it helps!!!
Mike

Similar Messages

  • I am getting a Firewall message that says...

    This one is for the PRO's.    I wonder if anyone can help me with this.
    I am getting a Firewall message that reads:
    The service "(Common Internet File System (CIFS))" is starting on your Mac.
    Application:  sbin > launchd
              Port:   445 (Common Internet File System (CIFS))
    It also says:  if you don't change firewall settings, the firewall wil block connections from other computers to this ervice on your Mac.
    What does this mean?  I never got this before.
    Thank you in advance for your help!

    According to this,
    Well known TCP and UDP ports used by Apple software products
    port 445 is for a Microsoft domain server.  So it looks like some microsoft software is trying to "call home" for some reason.
    If I saw that on my machine I would block it or not let it through.  I don't permit stuff communicating with third parties unless I am aware of what it is and why it is happening.
    Of course, out of curiousity I would also google "Common Internet File System" to see what that means in case I decide to let it through.
    FWIW, one of those google search hits found this.  So you know what microsoft stuff you are using and thus you have decide whether to let it though.  YOu could be concervative, and block it and see what "breaks" if anything.  You could always decide to unblock it later if necessary.

  • Firewall message sharing from Organizer to Facebook

    Firewall message in Elements Organizer when trying to share photos to Facebook.   Have used it many times in the past with no problems.

    Me also.  In the past no problem.  Went to use it today, and it won't work.  It states I either am NOT connected to the internet, which I am; or the firewall is preventing, which it isn't.  This is very frustrating....  From the posts now, I see, its a photoshop/facebook problem....I hope they fix it FAST !!!

  • Norton Personal Firewall messages at startup won't go away

    I used to have Norton Personal Firewall (NPF) installed on my G5 iMac. For some time now, whenever I start up, I get two messages related to NPF. The first one says that I have installed new system software and need to restart my computer. The second one says that NPF "cannot launch the kernel extension" and that "some features of NPF may not be enabled."
    I have been just ignoring and closing both of these messages, but recently I have been doing a cleanup, deleting files I don't need any more, and when I recently upgraded my Norton Antivirus software, I decided that NPF was superfluous, since Mac OS Leopard (10.5.5) has its own firewall. I tried to use the Norton uninstaller to delete the program, but the uninstaller does not list NPF in its list of applications to uninstall. I have done a Spotlight search for any NPF-related files and have also deleted all my old System 9 folders. I'm still getting these messages, though. Has anyone else ever seen this problem, and do you have any suggestions?
    Thanks!

    Thank you very much, but this is an older version (1.0.2) of the Symantec Uninstaller that came with NAV (1.1.1). As I mentioned, when I open Uninstaller and it searches for installed applications, Norton Personal Firewall does not show up in the list. So I can't use the Uninstaller to uninstall NPF. But I appreciate your attempt to help me.
    I wonder if somehow there are still some "residual" files remaining from NPF? If so, I have no idea how to find them, since they don't show up with a Spotlight search. Maybe it is something that is somehow embedded in the System?

  • Firewall Message with Airtunes and AppleTV

    I am using iTunes 8.02 on a Mac running Tiger 10.4.11. I like to stream my music to my AppleTV (which is running the most recent version of the firmware). My wireless router is an Airport Express (running the latest v6.3 software).
    In iTunes, I see a drop down menu showing me my AppleTV. When I select it, I see a pop up warning message:
    "Your Computers firewall settings will prevent you from using Airtunes.
    Please check your Firewall settings
    Learn More Ignore Open Firewall Settings"
    I click ignore and it works!!
    But Why am I getting this message?
    I have followed the instructions in:
    http://support.apple.com/kb/TS2278
    I have even disabled "Stealth Mode" in Tiger's firewall suggested in the forums.
    What am I missing?
    Why do I still get this warning message (yet it works when I click Ignore)?
    Rob

    Then I would be wireless from G5 and AppleTV to the internet. But I would loose the AirTunes / Express capability?
    You could only have one function at one time. (So you can't use your G5 and Apple TV on the internet while using AirTunes) as (AFAIK) the AirPort express can't be used as a 'wireless access point' at the same time as AirTunes.
    To try and summarize
    If you want to use AirTunes and have your computer and Apple TV connected to the same network with internet connectivity at the same time you can:
    1. Purchase an AirPort Extreme base station.
    2. Connect your cable modem to the AirPort extreme via ethernet, set up a WiFI network and connect your G5 and Apple TV.
    3. Join your AirPort express to the AirPort extreme network via client mode.
    http://docs.info.apple.com/article.html?artnum=108038#6

  • Constant Firewall messages

    I just did an upgrade to 10.6.2
    On checking Console, I see hundreds of messages like this:
    23/12/2009 16:51:37 Firewall[109] Allow smbd connecting from 10.0.0.5:49649 to port 139 proto=6
    and
    23/12/2009 16:55:14 Firewall[109] Stealth Mode connection attempt to UDP 10.0.0.14:64140 from 10.0.0.2:53
    Is this something to worry about?
    I'm not sure what these mean and if it's a problem? Is someone hacking into my system?

    +23/12/2009 16:51:37 Firewall109 Allow smbd connecting from 10.0.0.5:49649 to port 139 proto=6+
    This is the samba (windows client) network (lan) software trying to connect to your Mac's netbios
    port to determine the machine's identity. Samba is included with SL.
    +23/12/2009 16:55:14 Firewall109 Stealth Mode connection attempt to UDP 10.0.0.14:64140 from 10.0.0.2:53+
    This is your router (or modem/router combo) DNS (Domain Name Server) Service (on your router)
    trying to communicate with your Mac and your SL firewall is blocking it. Don't worry though, when
    your Mac needs DNS Services, it will ask for them. Actually it's probably your IP's nosy Web Server
    that's trying to connect to your Machine, as all DNS requests normally get channeled from your
    IP through your router. In other words, don't worry about it. All that means is your Snowie
    firewall is doing its job keeping out some nosy server, most likely belonging to your IP provider.
    Kj ♘

  • Firewall message

    I am getting a message "master is listening on .........
    Does this mean someone is accessing my computer?
    What is at risk?

    HI and Welcome to Apple Discussions...
    What application do you have open when this occurs? Is this a dialog box or audio? How do you know this is related to the Firewall ????
    If would help us to help you if you could update your profile. Please add the Mac OS X version number and which Mac you have. Thanks!
    Carolyn
    Message was edited by: Carolyn Samit

  • Bizarre FIrewall Message

    Starting up Airtunes brings up a warning dialogue that tells me my Firewall settings will prevent Airtunes from working. When I press the button to open up Firewall settings everything (including permitting Airtunes) looks right.
    If I try to go to network settings a warning dialogue appears telling me "The Settings have been changed by another application". Hitting the "close" button on the dialogue just makes the window pop up again. The only way I can leave the Network Settings window is to force quit System Preferences.
    By the way, Airtunes works fine if I just ignore the warning and play my songs.

    Same here.
    Jesdad, you might want to look into a few threads that deal with the network setting problem like these ones:
    http://discussions.apple.com/thread.jspa?threadID=1715241&tstart=0
    http://discussions.apple.com/thread.jspa?threadID=1716357&start=0&tstart=0
    Doing the lock-unlock trick saved me from the pop up but somehow my network settings are still corrupted and I get the same iTunes error messages that you describe.

  • "Lost connection to Firewall" message in ASDM Device Dashboard and Firewall Dashboard

    Question: I see this message for CPU,MEMORY,TRAFFIC,INTERFACE Stats.Any ideas ?Eveything is working except I see this message.
    It has ASA 5540 VER 8.2 and ASDM 6.2
    Thanks

    This is probably bug CSCta49088.
    Did you try to reload the ASA?
    you might need to open a TAC case so they can provide you with an image that fixes it.
    I hope it helps.
    PK

  • Since changing our computer I have been unable to download ebooks to my Reader Library I get a message Some file types associated with EPUB files are not associated with Reader Library; Waterstones suggest that I may have accidentally created a new Adobe

    When I try to download them from the Waterstones website I get a message saying:
    ‘Some file types associated with EPUB files are not associated with Reader Library.  Do you want to associate them now?  When I reply yes I get another message; ‘Configuration error unable to update EPUB files check network firewall and try again’.
    The ‘books’ are saved in the Download directory and I can’t transfer them from there to my E-Reader. I have not had any problems before, it was very simple; I saved the download and it automatically went into the Reader Library.
    I contacted HP and they said it is a software error and suggested I contact Waterstones.  I contacted Waterstones Customer Support and got the following response:
    As the error message is specifically mentioning the firewall it does sound like something in the firewall settings is stopping the download from taking place correctly. However, the files should not be being saved to the Download folder. It would be worth trying again by going to your Digital Order History on your Waterstones.com account and pressing the download button, and then making sure to press "Open" not "Save". When you press Open rather than Save it should give the option to open the file with Adobe Digital Editions. If the firewall message still comes up then I'm afraid something is blocking it on your end.
    If the above "Open" download method works but you then still get an error message it could possibly be that you have accidentally created a new Adobe ID when setting up on the new computer, rather than signing in with your old Adobe ID. It would be worth trying the aforementioned download technique again first, but if problems did still persist it would be worth calling Adobe themselves on 0207 365 0735, as they should be able to sort out any account issue.
      In response to the first para of Waterstones email I already do what they suggest I do press ‘Open’ not ‘Save’ but I don’t get the open with Adobe Digital Editions (we have installed Adobe Digital Editions on the new computer. Waterstones say we may have ‘accidentally created a new Adobe ID when setting up the new computer’ does that mean that we shouldn’t have installed Adobe Digital Editions on the new computer as it would have already been there? How do I sign in with my old Adobe ID? 

    Hi all after attampting to get some supoport from adobe by phone.... nice people infurating policys as far as support for digital editions or DRM is conserned... However I got no where with support.
    I ended up instaling Digital editions on my desktop PC and going through the motions of registering and borrowing a book then returning it. Then I trying on my iPad, Bluefire worked, Over drive did not so I completely removed Overdrive and reinstalled and re registered. all working now.
    Maybe some one at adobe did something. Maybe the install of the adobe DE client on a PC corrected what ever was out of wack with my account. Mayby the server that my account lives on did a scan disk and corrected a bad clustrer.
    What ever happend My account is actiove and working again. hope this helps others.

  • Can't connect to wireless networks without disabling firewall.

    I just had the built-in battery replaced on my MBP by the genius bar. When I started the machine up I was bombarded with firewall messages asking if applications should be given access to incoming network connections. I didn't recognize a few of them and clicked "deny". Now my machine will no longer connect to a wireless network without first disabling the firewall. Then I can re-enable the firewall and it seems to work okay.
    I went through the Security panel and edited the list of applications allowed to have incoming connections and enabled all the ones that were disabled hoping that would fix it. The only one that is disabled now is OSXVNC, which I don't use and don't want to be enabled.
    I'm not sure why replacing the battery caused all the windows to pop up, but now I don't know how to fix this issue. Anyone have any advice? Is there a way to restore my old firewall settings?

    Go to the /Macintosh HD/Library/Preferences/ folder and remove the file called "com.apple.alf.plist", then restart your system.
    This file is the preferences file for the application firewall. Removing it will clear all the firewall rules and set up the firewall from scratch. Sometimes after hardware configuration changes, or even hard crashes the firewall may not work properly and removing this file to set it up from scratch should do the trick. It will still ask you to allow some services and applications after doing this, but should not ask to for every system service and feature that uses the network.

  • When I run a diagnostic on my network connection, Itunes says that a secure connection was not found giving the following message.  Microsoft Windows Vista Home Premium Edition Service Pack 2 (Build 6002) Hewlett-Packard HP Pavilion dv6700 Notebook PC iTu

    Microsoft Windows Vista Home Premium Edition Service Pack 2 (Build 6002)
    Hewlett-Packard HP Pavilion dv6700 Notebook PC
    iTunes 10.2.1.1
    QuickTime 7.6.9
    FairPlay 1.11.16
    Apple Application Support 1.5
    iPod Updater Library 10.0d2
    VoiceOver Kit 1.4 (222093/222742)
    CD Driver 2.2.0.1
    CD Driver DLL 2.1.1.1
    Apple Mobile Device 3.4.0.25
    Apple Mobile Device Driver 1.55.0.0
    Bonjour 2.0.4.0 (214.3)
    Gracenote SDK 1.8.2.457
    Gracenote MusicID 1.8.2.89
    Gracenote Submit 1.8.2.123
    Gracenote DSP 1.8.2.34
    iTunes Serial Number 0025AAF8089EC380
    Current user is not an administrator.
    The current local date and time is 2011-05-15 21:05:05.
    iTunes is not running in safe mode.
    WebKit accelerated compositing is enabled.
    HDCP is not supported.
    Core Media is supported.
    Video Display Information
    Intel Corporation, Mobile Intel(R) 965 Express Chipset Family
    Intel Corporation, Mobile Intel(R) 965 Express Chipset Family
    **** External Plug-ins Information ****
    No external plug-ins installed.
    Genius ID: dc0c6f739bfede483c8983f10e41784f
    iPodService 10.2.1.1 is currently running.
    iTunesHelper 10.2.1.1 is currently running.
    Apple Mobile Device service 3.3.0.0 is currently running.
    **** Network Connectivity Tests ****
    Network Adapter Information
    Adapter Name:    {588EB1BD-8374-43B1-B687-C47C33764298}
    Description:    Intel(R) Wireless WiFi Link 4965AGN
    IP Address:    192.168.1.2
    Subnet Mask:    255.255.255.0
    Default Gateway:    192.168.1.1
    DHCP Enabled:    Yes
    DHCP Server:    192.168.1.1
    Lease Obtained:    Sun May 15 20:23:07 2011
    Lease Expires:    Mon May 16 20:23:07 2011
    DNS Servers:    192.168.1.1
    Adapter Name:    {1C11AE53-28A5-4AC7-BA9F-CD4109D7856C}
    Description:    Realtek RTL8101E Family PCI-E Fast Ethernet NIC (NDIS 6.0)
    IP Address:    0.0.0.0
    Subnet Mask:    0.0.0.0
    Default Gateway:    0.0.0.0
    DHCP Enabled:    Yes
    DHCP Server:   
    Lease Obtained:    Wed Dec 31 18:00:00 1969
    Lease Expires:    Wed Dec 31 18:00:00 1969
    DNS Servers:   
    Active Connection:    LAN Connection
    Connected:    Yes
    Online:        Yes
    Using Modem:    No
    Using LAN:    Yes
    Using Proxy:    No
    SSL 3.0 Support:    Enabled
    TLS 1.0 Support:    Enabled
    Firewall Information
    Windows Firewall is on.
    iTunes is NOT enabled in Windows Firewall.
    Connection attempt to Apple web site was unsuccessful.
    The network connection timed out.
    Basic connection to the store failed.
    The network connection timed out.
    Connection attempt to Gracenote server was successful.
    The network connection timed out.
    Last successful iTunes Store access was 2011-04-30 21:01:11.

    Windows Firewall is on.
    iTunes is NOT enabled in Windows Firewall.
    We'd better check on that, kris. If you enable iTunes in your Windows firewall, does that help with your connection? See the following document for instructions:
    How to enable iTunes in the Windows XP Firewall
    EDIT: Drat ... gave you the link to the wrong document. Try this one instead for your Vista:
    How to enable iTunes in the Windows Vista and Windows 7 Firewall
    Message was edited by: b noir

  • Audition and windows firewall

    I've scrapped the security I've been using on my machine in favor of Microsoft Security Essentials.  I've also enabled Windows Firewall to see how it works.  (I've got a router, so I haven't been using a firewall, but I wanted to see what effect it might have.)  Okay, so I tried loading a third-party plugin into a CS6 session, and I get a Windows Security Alert telling me 'Windows Firewall has blocked some features of this program', and it describes Audition, not the third-party plugin, as the reason.
    Okay, why would it do that? 
    It gives me this option if I want it: 'Allow Adobe Audition CS6 to communicate on these networks:
    * Private networks, such as my home or work network.
    * Public networks...'
    Okay, communicate?  What does Audition communicate with when I'm online?  Is it just the online Help?  And why would Windows Firewall block that?

    Audition is simply communicating with a separate headless app that comes with Audition that does the plug-in scanning.  Because there's a lot of bad plug-ins out there that can crash an application simply by scanning them, we created the separate app that does all of our plug-in scanning in the background.  They have to be separate to keep Audition from crashing on bad plug-ins during scan.  So the network activity that the firewall is complaining about is simply Audition talking to the dvaaudiofilterscan application in the background that is on a localhost port (i.e. same machine, not talking to anything outside your computer).
    The same goes for the dynamiclinkmediaserver (aka DLMS) which loads certain files in a separate application because it uses importer code from Premiere Pro (the most recent versions of Photoshop and Lightroom also use DLMS).
    Lastly, you may sometimes see a firewall message if you have EUCON control surface devices because they talk to the computer via ethernet.  So if you choose the EUCON control surface plug-in, that can spawn firewall messages as well.

  • ARDAgent - Application Firewall: allow incoming connections alert won't stop

    Hello,
    after having updated Remote Desktop Client from 3.8 to 3.8.2, users have to allow (or deny) incoming connections within the Firewall settings
    WHENEVER starting the /System/Library/CoreServices/RemoteManagement/ARDAgent.app, especially when logging in or starting the /Applications/Remote\ Desktop.app (Admin)
    ALTHOUGH
    /System/Library/CoreServices/RemoteManagement/ARDAgent.app is locked in the Firewall Settings AND/or
    "Automatically allow signed Software to receive incoming connections" is checked (enabled)
    When switching to a standard user (not an admin), he also can/must allow or deny - and the Firewall Settings are modified correspondingly.
    My questions are so far:
    Why the existing Firewall Setting does not affect when (re-)starting the ARDagent.app-deamon?
    Is the ARDagent.app (since Version 3.8.2) not a signed software?
    This kind of attitude occurs for OS X 10.10.1 _and_ OS X 10.10.2.
    Many thanks for any approach to overcome the problem and kind regards from Munich (GER).

    I was fighting with this 'till now.
    This is what I did:
    Remove ARDagent.app from /System/Library/CoreServices/RemoteManagement
    Remove it from the list in Firewall preferences.
    Disable Firewall.
    Reboot.
    Install OSX 10.10.2 combo-update.
    Reboot.
    Add manually the ARDagent.app to the Allowed Rules in Firewall from /System/Library/CoreServices/RemoteManagement
    Enable Firewall.
    Update to ARD Client v3.8.2 v1.1 from the App Store.
    Reboot.
    Here, the annoying firewall message has gone. I hope it will work for you too.
    I know it's a bit raw and it can be done in a more sophisticated way... But I have no time to deal with this kind of sh*t!
    Cheers.

  • TS1629 OS 10.8 Firewall is now blocking my 1st gen Apple TV from syncing with my iMac, how do I fix this?

    Here is the specific error message:
    "The Apple TV "Apple TV" is not responding. Check that any firewall software running on this computer has been set to allow communication on port 3689"
    I'm not running a 3rd pary firewall and my router is an Airport Extreme.  This worked until I upgraded yesterday to Mountain Lion.

    Quiting iTunes and opening it again works for me too but what a pain.  I have my computer set to require a password after the screen saver has been on for more than a minute.  I find that my Apple TV gen 1 will stay connected as long I'm logged in but after my account is locked when my computer goies idle at some point the connection is lost.  Even when I log in again and go to sync the Apple TV I get the firewall message.  I have no firewall enabled and I believe I have the proper port open on my router.

Maybe you are looking for

  • When I sign in the iMessage in my macbook pro will it send me the alert message too?

    When I sign in phone account in the iMessage in my macbook pro will it send the alert message to my iphone device too?

  • Error in Back date delivery

    Hi All, I want to create one Order in Back date with back date delivery(Picking + PGI) and Billing, i m able to create the Order& Billing  in Back date but when i enter the back delivery date in sales order it will create current date's schedule line

  • Wish list for iPad films

    Is it possible to have an 'add to wish list' button for films on the iPad? I search through films and would love to add a range of films to a wish list so I can download them when I have a fast broadband connection. Thanks

  • Difference between SYNC/ASYNC, LGWR/ARCH, and AFFIRM/NOAFFIRM?

    Hi all ; I need some basic information about following things in data guard.(oracle 10g). difference between SYNC/ASYNC, LGWR/ARCH, and AFFIRM/NOAFFIRM?

  • Broken images in photo stream in iPhoto on iMac

    I don't know where these images are coming from but they look like broken images from the internet. I can't delete them because they are on my photostream. I've reset my photo stream on my other devices but the broken images are still there and it ha