RSA Admin

Excluding private IP address space in a firewall report

Discussion created by RSA Admin Employee on Oct 20, 2009
Latest reply on Oct 20, 2009 by RSA Admin

I'm not sure how to accomplish this in a report.  I am trying to exclude the private IP address space from a firewall report.  I have some Checkpoint Firewalls I am interested in looking at.  I am using the Firewall Accounting table and the ForeignAddress field.

 

My SQL where clause looks like this:

 

ForeignAddress NOT IN

('10.%.%.%','172.16.%.%','172.17.%.%','172.18.%.%','172.19.%.%',

'172.20.%.%','172.21.%.%','172.22.%.%','172.23.%.%','172.24.%.%',

'172.25.%.%','172.26.%.%','172.27.%.%','172.28.%.%','172.29.%.%',

'172.30.%.%','172.31.%.%','192.168.%.%')

 

The report run fine, but still shows Foreign Addresses in the private ranges.  Is there something I am doing wrong here?  Thanks in advance for your help.

Message Edited by CaptainJackSparrow on10-20-200908:45 AM

Outcomes