What do “blocked”, “denied” and “dropped” mean in a firewall log?¶
These labels mean that the firewall did not allow the recorded traffic to pass at that control point. They do not describe what happened elsewhere.
The short version¶
A blocked entry may show an attempted packet or connection being stopped. It does not prove that a complete connection existed, that an attack occurred or that the protected system was compromised.
“Dropped” often means discarded without a response. “Rejected” may mean blocked with a response. Product terminology varies, so confirm the vendor’s meaning.
Interpret the pattern¶
Internet-facing systems receive automated scanning, misconfiguration and background noise as well as deliberate targeting. Look at timing, repetition, destination ports and related allowed activity before describing intent.
A blocked attempt may show that a control worked, but it does not prove the whole network was safe. Other routes, rules or earlier activity remain separate questions.
Safe wording¶
The firewall recorded and blocked traffic from this source towards this destination and port.
The point to remember
Blocked, denied and dropped describe one firewall decision. They do not establish who sent the traffic, why it was sent or what happened elsewhere.