How to convert an IP address from the firewall log into a dotted IP address in Internet Security and Acceleration Server or in Microsoft Forefront Threat Management Gateway, Medium Business Edition

Article translations Article translations
Article ID: 891223 - View products that this article applies to.
Expand all | Collapse all

INTRODUCTION

This article discusses how to convert an IP address from the Microsoft Internet Security and Acceleration (ISA) Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition firewall log into a dotted IP address by using SQL Query Analyzer to query the firewall log database.

MORE INFORMATION

To convert an IP address from an ISA Server 2004 firewall log into a dotted IP address, use the following SQL statement in SQL Query Analyzer:
SELECT 

CAST(SourceIP / 256 / 256 / 256 % 256 AS VARCHAR) + '.' + 

CAST(SourceIP / 256 / 256 % 256 AS VARCHAR) + '.' + 

CAST(SourceIP / 256 % 256 AS VARCHAR) + '.' + 

CAST(SourceIP % 256 AS VARCHAR) 

AS [Nice Source Ip], FirewallLog.*

From FirewallLog
The SourceIP field of the FirewallLog table is defined using the BigInt data type. For example, if the value of the SourceIP field is 172.16.1.1, the table will store the data value as 2886729985.

Note FirewallLog is the table name for the Firewall log, and WebProxyLog is the table name for the Web Proxy log.

Properties

Article ID: 891223 - Last Review: August 15, 2006 - Revision: 2.1
APPLIES TO
  • Microsoft Internet Security and Acceleration Server 2004 Standard Edition
  • Microsoft Forefront Threat Management Gateway, Medium Business Edition
Keywords: 
kbdatabase kbhowto KB891223

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com