Here are some sample green lines from the log file:
00:01:37 TCP from 212.55.179.166:4212 to XX.XXX.XXX.XXX:3127
00:01:41 UDP from 221.232.160.103:777 to XX.XXX.XXX.XXX:1026
00:05:25 TCP from 4.12.193.243:3608 to XX.XXX.XXX.XXX:20168
00:23:06 UDP from 204.209.71.164:24419 to XX.XXX.XXX.XXX:1029
01:07:11 TCP from 200.66.99.5:1750 to XX.XXX.XXX.XXX:3127
01:13:28 UDP from 207.36.181.131:3456 to XX.XXX.XXX.XXX:1026
01:17:39 TCP from 80.128.129.72:3695 to XX.XXX.XXX.XXX:6129
01:20:25 TCP from 64.1.43.66:220 to XX.XXX.XXX.XXX:6129
01:26:05 TCP from 218.26.187.22:3079 to XX.XXX.XXX.XXX:4899
01:42:08 UDP from 209.123.112.111:13798 to XX.XXX.XXX.XXX:1026
01:42:08 UDP from 209.122.157.209:9599 to XX.XXX.XXX.XXX:1027
02:15:36 UDP from 61.17.107.71:777 to XX.XXX.XXX.XXX:1026
02:16:51 UDP from 204.78.8.141:21562 to XX.XXX.XXX.XXX:1028
02:19:26 UDP from 195.22.22.36:3235 to XX.XXX.XXX.XXX:1434
02:27:24 UDP from 221.232.160.103:777 to XX.XXX.XXX.XXX:1026
02:30:21 TCP from 82.64.66.86:1969 to XX.XXX.XXX.XXX:901
02:32:21 UDP from 64.253.170.82:16819 to XX.XXX.XXX.XXX:1026
02:43:51 TCP from 4.33.202.34:3481 to XX.XXX.XXX.XXX:6129
The XX.XXX.XXX.XXX is my WAN ip address. To me this looks like incoming traffic? These green messages are appearing mainly while I'm not on the computer. To my knowledge I'm not actively soliciting anything from the web (I turned off the Norton Live Update to be sure) while I'm not on the computer, but there could be requests being made that I'm not aware of.
Outgoing requests (say, to look at the weather as an example) look like the following:
02:50:21 TCP from 192.168.1.100:4146 to
www.w3.weather.com(63.111.66.24):80
02:50:26 TCP from 192.168.1.100:4148 to
www.weather.com(63.111.24.20):80
02:50:26 TCP from 192.168.1.100:4150 to
www.w2.weather.com(63.111.24.22):80
02:50:28 TCP from 192.168.1.100:4152 to
www.w3.weather.com(63.111.66.24):80
I generally don't see any additional incoming traffic while I'm on the web.
A typical red line of traffic which shows up as being blocked by the firewall looks as follows:
03:42:31 4459/TCP from 64.236.16.138:80 to 192.168.1.100:4459 Invalid TCP packet received, dropping packet