1 ip 0x11 10.133.120.145 213.212.65.205 514 514 500514 12.05% 2 ip 0x01 216.203.2.133 60.9.185.16 11 0 468402 11.28%
1: Is there any specific reason why syslog is using source port 514 instead of any random port greater than 1024?
2: Is ICMP traffic between 216.203.2.133 & 60.9.185.16 legitimate ?
Thanks,
Vikas