<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Firewall Log interpretation</title><link>https://community.sophos.com/utm-firewall/f/network-protection-firewall-nat-qos-ips/90711/firewall-log-interpretation</link><description>Hi there, 
 Thanx in advance for helping me understand Sophos UTM firewall/packagefilter a little more. 
 
 Having kind a hard time to interpret some firewall logs on my utm 9.411-3. Maybe there is something wrong, maybe i am just not getting the concept</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Firewall Log interpretation</title><link>https://community.sophos.com/thread/329283?ContentTypeID=1</link><pubDate>Wed, 12 Apr 2017 11:56:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:41593234-d5fb-48d0-b283-8947ddbe7eb6</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Hi, Sebastiaan, and welcome to the UTM Community!&lt;/p&gt;
&lt;p&gt;As Dirk says, the MAC addresses represent the next physical hop to reach an IP - your ISP&amp;#39;s router and your internal switch.&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Firewall Log interpretation</title><link>https://community.sophos.com/thread/328814?ContentTypeID=1</link><pubDate>Fri, 07 Apr 2017 13:52:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4ab29f13-dbd8-486a-a72d-73878ff92042</guid><dc:creator>dirkkotte</dc:creator><description>&lt;p&gt;That&amp;#39;s OK. Thats how IP-routing works.&lt;/p&gt;
&lt;p&gt;within LAN (same subnet) you see the MAC for every device.&lt;/p&gt;
&lt;p&gt;With routing you see the MAC of the router for all IP&amp;#39;s behind this device.&lt;/p&gt;
&lt;p&gt;This can be explained with OSI 7 layer model...&lt;/p&gt;
&lt;p&gt;&lt;a href="https://support.microsoft.com/de-de/help/103884/the-osi-model-s-seven-layers-defined-and-functions-explained"&gt;https://support.microsoft.com/de-de/help/103884/the-osi-model-s-seven-layers-defined-and-functions-explained&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The MAC address within packet are from L2. The L2 don#t know something from L3(IP). Here we see only communication between direct linked devices. (Router&amp;lt;-&amp;gt;Firewall or Firewall&amp;lt;-&amp;gt;endsystem)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>