Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What does “allowed” mean in a firewall log?

“Allowed” means that this firewall applied its rules and did not block the traffic represented by the entry.

What it does not mean

It does not by itself prove that:

  • a complete connection was established;
  • the destination service was running;
  • a login succeeded;
  • data was transferred; or
  • a person performed an action.

The traffic may have failed later, been blocked by another control or been rejected by the destination application.

Read the record type

A single allowed packet is weaker than a session record showing traffic in both directions, duration or bytes. TCP and UDP also behave differently: allowing an initial TCP packet is not the same as proving a completed connection, while UDP does not use the same handshake.

Safe wording

If the firewall entry is all you have:

The firewall recorded and allowed traffic from this source towards this destination and port.

Do not silently upgrade that to “the user connected” or “the user accessed the service”. Look for destination logs, session evidence and application records before making that claim.

The point to remember

“Allowed” describes one control decision at one observation point. It is not the final outcome and it is not identity evidence.

Reference: IP-100IP Addresses & Networks