×
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
nomizzz
Contributor
Message 1 of 3

Internet Security Suite Firewall Not Logging Certain ICMP Incoming Events

While testing my network security on one of my Windows 7 PCs, I enabled all the firewall event logging and then performed a series of port scans from another PC on my network running Ubuntu Linux.  I used the program nmap to perform specific ICMP pings, but none of them registered in the Inbound Events section of the Internet & Network event log.  Interestingly, my other Windows 7 computers' ICMP periodic pings (from the Windows 7 homegroup services) do show up in the log.

Here is the actual tests I've performed and their results, which clearly show that the defending computer (192.168.1.82) responded to these inbound events even though they did not get logged.

simon@extensa5620:~$ sudo nmap -sP -PP 192.168.1.82

Starting Nmap 5.00 ( http://nmap.org ) at 2010-06-11 13:27 EDT
Host GTACOMPACC09 (192.168.1.82) is up (0.071s latency).
MAC Address: **REMOVED** (Cisco-Linksys)
Nmap done: 1 IP address (1 host up) scanned in 0.24 seconds
simon@extensa5620:~$ sudo nmap -sP -PM 192.168.1.82

Starting Nmap 5.00 ( http://nmap.org ) at 2010-06-11 13:27 EDT
Host GTACOMPACC09 (192.168.1.82) is up (0.026s latency).
MAC Address: **REMOVED** (Cisco-Linksys)
Nmap done: 1 IP address (1 host up) scanned in 0.22 seconds
simon@extensa5620:~$ ping 192.168.1.82
PING 192.168.1.82 (192.168.1.82) 56(84) bytes of data.
64 bytes from 192.168.1.82: icmp_seq=1 ttl=128 time=2.25 ms
64 bytes from 192.168.1.82: icmp_seq=2 ttl=128 time=4.58 ms
64 bytes from 192.168.1.82: icmp_seq=3 ttl=128 time=3.37 ms
64 bytes from 192.168.1.82: icmp_seq=4 ttl=128 time=3.25 ms
64 bytes from 192.168.1.82: icmp_seq=5 ttl=128 time=3.15 ms
64 bytes from 192.168.1.82: icmp_seq=6 ttl=128 time=3.13 ms
^C
--- 192.168.1.82 ping statistics ---
6 packets transmitted, 6 received, 0% packet loss, time 5007ms
rtt min/avg/max/mdev = 2.259/3.293/4.581/0.681 ms

mcafee.png

FYI the -PP and -PM arguments to nmap perform adress and timestamp ICMP  requests, respectively.  Note that my linux box's IPv4 is : 192.168.1.148 and its IPv6 is : fe80::21c:bfff:fe56:1227/64

Could this issue be related to the fact that my McAfee event log seems to log all events in IPv6 format whereas my linux box is accessing it from IPv4?  If so, how can I force McAfee to log IPv4 events?

2 Replies
nomizzz
Contributor
Message 2 of 3

Re: Internet Security Suite Firewall Not Logging Certain ICMP Incoming Events

Any ideas anyone?  I still can't figure this one out...

k3tg
Reliable Contributor
Reliable Contributor
Message 3 of 3

Re: Internet Security Suite Firewall Not Logging Certain ICMP Incoming Events

You could try contacting Technical Support Chat found at the top of this page under Useful Links. They are available 24/7 and could provide you some answers to your questions.

How Many Badges Can You Collect?
Ready for a little competition? Members like you are earning badges and unlocking perks for their helpful answers. Are you? Click here to find out.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community