Advertisement
Guest User

Untitled

a guest
Apr 17th, 2019
125
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. <140>Apr 17 07:53:46 EviivoFB5 801403807398F (2019-04-17T12:53:46) firewall: msg_id="3000-0148" Deny 80-DATA Firebox 145 udp 20 250 10.50.10.2 255.255.255.255 61111 61111  (Unhandled Internal Packet-00)<142>Apr 17 07:53:47 EviivoFB5 801403807398F (2019-04-17T12:53:47) https-proxy[2427]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.16 52.109.124.21 50788 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="nexus.officeapps.live.com" cn="nexus.officeapps.live.com" cert_issuer="CN=Microsoft IT TLS CA 5,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=nexus.officeapps.live.com" action="allow" app_id="0" app_cat_id="0" sent_bytes="985" rcvd_bytes="6486"  (HTTPS-proxy-00)<142>Apr 17 07:53:49 EviivoFB5 801403807398F (2019-04-17T12:53:49) https-proxy[2424]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.16 52.109.12.20 50789 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="nexusrules.officeapps.live.com" cn="nexusrules.officeapps.live.com" cert_issuer="CN=Microsoft IT TLS CA 4,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=nexusrules.officeapps.live.com" action="allow" app_id="0" app_cat_id="0" sent_bytes="1006" rcvd_bytes="6181"  (HTTPS-proxy-00)<142>Apr 17 07:53:54 EviivoFB5 801403807398F (2019-04-17T12:53:54) https-proxy[2424]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.11 52.178.207.179 58040 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="static.asm.skype.com" cn="static.asm.skype.com" cert_issuer="CN=Microsoft IT TLS CA 5,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=static.asm.skype.com" action="allow" app_id="0" app_cat_id="0" sent_bytes="2011" rcvd_bytes="6405"  (HTTPS-proxy-00)<142>Apr 17 07:53:58 EviivoFB5 801403807398F (2019-04-17T12:53:58) https-proxy[2426]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.31 40.67.254.36 50012 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="client.wns.windows.com" cn="*.wns.windows.com" cert_issuer="CN=Microsoft IT TLS CA 5,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=*.wns.windows.com" action="allow" app_id="0" app_cat_id="0" sent_bytes="5001" rcvd_bytes="5508"  (HTTPS-proxy-00)<142>Apr 17 07:53:59 EviivoFB5 801403807398F (2019-04-17T12:53:59) https-proxy[2427]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.31 68.232.34.200 50236 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="static-asm.secure.skypeassets.com" cn="*.vo.msecnd.net" cert_issuer="CN=Microsoft IT TLS CA 2,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=*.vo.msecnd.net" action="allow" app_id="0" app_cat_id="0" sent_bytes="1126" rcvd_bytes="9894"  (HTTPS-proxy-00)<140>Apr 17 07:54:01 EviivoFB5 801403807398F (2019-04-17T12:54:01) firewall: msg_id="3000-0148" Deny 80-DATA Firebox 229 udp 20 128 10.50.10.16 10.50.10.255 138 138  (Unhandled Internal Packet-00)<140>Apr 17 07:54:02 EviivoFB5 801403807398F (2019-04-17T12:54:02) firewall: msg_id="3000-0148" Deny 0-External Firebox 40 tcp 20 246 195.154.108.205 4.79.91.142 49617 25 offset 5 S 3083000671 win 4  (Unhandled External Packet-00)<142>Apr 17 07:54:08 EviivoFB5 801403807398F (2019-04-17T12:54:08) https-proxy[2425]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.11 52.109.76.8 58047 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="roaming.officeapps.live.com" cn="roaming.officeapps.live.com" cert_issuer="CN=Microsoft IT TLS CA 1,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=roaming.officeapps.live.com" action="allow" app_id="0" app_cat_id="0" sent_bytes="6731" rcvd_bytes="6972"  (HTTPS-proxy-00)<142>Apr 17 07:54:11 EviivoFB5 801403807398F (2019-04-17T12:54:11) https-proxy[2427]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.25 40.69.221.239 59419 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="array608-prod.do.dsp.mp.microsoft.com" cn="prod6.do.dsp.mp.microsoft.com" cert_issuer="CN=Microsoft ECC Content Distribution Secure Server CA 2.1,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=prod6.do.dsp.mp.microsoft.com,OU=DSP,O=Microsoft,L=Redmond,ST=WA,C=US" action="allow" app_id="0" app_cat_id="0" sent_bytes="1412" rcvd_bytes="4436"  (HTTPS-proxy-00)<140>Apr 17 07:54:12 EviivoFB5 801403807398F (2019-04-17T12:54:12) firewall: msg_id="3000-0148" Deny 0-External Firebox 40 tcp 20 242 194.28.112.50 4.79.91.142 43744 33923 offset 5 S 1398076905 win 4  (Unhandled External Packet-00)<140>Apr 17 07:54:13 EviivoFB5 801403807398F (2019-04-17T12:54:13) firewall: msg_id="3000-0148" Deny 0-External Firebox 40 tcp 20 244 185.200.118.49 4.79.91.142 35381 1723 offset 5 S 2412925994 win 65535  (Unhandled External Packet-00)<142>Apr 17 07:54:17 EviivoFB5 801403807398F (2019-04-17T12:54:17) https-proxy[2425]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.24 52.178.192.146 55375 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="array601-prod.do.dsp.mp.microsoft.com" cn="prod6.do.dsp.mp.microsoft.com" cert_issuer="CN=Microsoft ECC Content Distribution Secure Server CA 2.1,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=prod6.do.dsp.mp.microsoft.com,OU=DSP,O=Microsoft,L=Redmond,ST=WA,C=US" action="allow" app_id="0" app_cat_id="0" sent_bytes="1369" rcvd_bytes="4435"  (HTTPS-proxy-00)<142>Apr 17 07:54:23 EviivoFB5 801403807398F (2019-04-17T12:54:23) https-proxy[2426]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.31 52.114.7.37 50225 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="browser.pipe.aria.microsoft.com" cn="*.events.data.microsoft.com" cert_issuer="CN=Microsoft IT TLS CA 2,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=*.events.data.microsoft.com" action="allow" app_id="0" app_cat_id="0" sent_bytes="22800" rcvd_bytes="8568"  (HTTPS-proxy-00)<140>Apr 17 07:54:24 EviivoFB5 801403807398F (2019-04-17T12:54:24) firewall: msg_id="3000-0148" Deny 80-DATA Firebox 71 tcp 20 64 10.50.10.2 17.142.169.199 52223 443 offset 5 A 1715967445 win 8 msg="tcp syn checking failed (expecting SYN packet for new TCP connection, but received ACK, FIN, or RST instead)."  (Internal Policy)<142>Apr 17 07:54:24 EviivoFB5 801403807398F (2019-04-17T12:54:24) https-proxy[2426]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.31 52.169.87.42 50246 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="array605-prod.do.dsp.mp.microsoft.com" cn="prod6.do.dsp.mp.microsoft.com" cert_issuer="CN=Microsoft ECC Content Distribution Secure Server CA 2.1,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=prod6.do.dsp.mp.microsoft.com,OU=DSP,O=Microsoft,L=Redmond,ST=WA,C=US" action="allow" app_id="0" app_cat_id="0" sent_bytes="1315" rcvd_bytes="4436"  (HTTPS-proxy-00)<142>Apr 17 07:54:33 EviivoFB5 801403807398F (2019-04-17T12:54:33) https-proxy[2426]: msg_id="2CFF-0000" Allow 80-DATA 0-External tcp 10.50.10.24 68.232.34.200 55373 443 msg="HTTPS Request" proxy_act="HTTPS-Client.Standard" tls_profile="TLS-Client-HTTPS.Standard" tls_version="TLS_V12" sni="static-asm.secure.skypeassets.com" cn="*.vo.msecnd.net" cert_issuer="CN=Microsoft IT TLS CA 2,OU=Microsoft IT,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US" cert_subject="CN=*.vo.msecnd.net" action="allow" app_id="0" app_cat_id="0" sent_bytes="1130" rcvd_bytes="9897"  (HTTPS-proxy-00)<140>Apr 17 07:54:34 EviivoFB5 801403807398F (2019-04-17T12:54:34) firewall: msg_id="3000-0148" Deny 0-External Firebox 40 tcp 20 247 207.244.86.222 4.79.91.142 55216 1787 offset 5 S 3692159024 win 4  (Unhandled External Packet-00)^C
  2. user@evisvrelk01:/usr/share/logstash$ sudo netcat -ul 514
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement