Reply
Regular Visitor
milen15
Posts: 5
Registered: ‎02-27-2011

NIS 2011 Firewall - Security History

Hi to all. This is my firs post and I need help. I have  NIS 2011 on Windows XP SP3, and when i open the history i see this

 

 

Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category,Program Name,Program Path,Default Action,Action Taken,Local Computer,Traffic Description,Windows Message ID/ Handle,Command Line,KeyLogger Type,Unrecognized Module
28.2.2011 г. 03:24,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 79.132.19.250, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:24,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 79.132.19.250, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 91.196.224.211, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 79.132.19.250, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 91.196.224.211, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 79.132.19.250, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 79.132.19.250, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port (3127) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port (73) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port (3128) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port http-proxy-1(8088) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port http-proxy(8080) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port (8123) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:23,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 60.173.11.56, local service  Port (8085) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:21,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 91.196.224.211, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.2.2011 г. 03:21,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 79.132.19.250, local service  Port (41754) .",Detected,No Action Required,Firewall - Activities,,,,,,,,,,
28.
and continue with more 16-17 pages of that,  I'm beginner with computers and don't know much honestly a little bit, i have no router, i have format partition c: twice and install again the windows, 1 time full scan with norton i made, one with norton online scanner, and 1 with bitdefender online scanner and nothing says it's clear.  
Please help.

 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: NIS 2011 Firewall - Security History

The look like fairly normal activities depending on where you are in the world. Some are likely your ISP, some are subnet traffic that is blocked in your machine but still recorded by Norton as to what was done with it.  If you have 16 or 17 pages, I would suggest clearing the data as it will slow down loading history.

 

The history to be most concerned with is Quarantine, Intrusion prevention and resolved and unresolved threats.  Even those can be cleared individually if there is nothing of interest.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
SendOfJive
Posts: 9,898
Kudos: 4,190
Solutions: 706
Registered: ‎02-07-2009

Re: NIS 2011 Firewall - Security History

Hi milen15,

 

The purpose of a firewall is to block unsolicited traffic from accessing your PC.  What you are seeing is the log report on what the Norton Firewall has been blocking.  There is a lot of background traffic on the internet and so you will see a lot of these types of entries.  This is normal and just shows the firewall doing what it is supposed to do.  If you had a router this traffic would be blocked at the router rather than by your Norton Firewall.  This would add an extra layer of security if you want to incur the modest extra expense, but you are still safe as long as you have the Norton Firewall enabled.