Hi all,
Well, at a glance:
R = Reset expired connections mostly seem to be from remote web servers
S = Port Scan most important to be recognised most seem to NetBios or MS-DS
ICMP = Remote computer sending ping packets to your IP
It is also possible to look at extended logging by right clicking any Firewall Hit and copying to the clipboard like these.
Wingate firewall hit report:
Time: 02/09/2007 21:53:31
Reason: Port Range
Source MAC address: 06-F6-20-00-03-00
Destination MAC address: 00-00-00-00-00-00
Source IP Address: 24.64.176.151 : 33609
Destination IP Address: 144.165.210.250 : 1026
Protocol: UDP
Time-to-live: 67
Wingate firewall hit report:
Time: 02/09/2007 21:41:52
Reason: Port Range
Source MAC address: 06-F6-20-00-03-00
Destination MAC address: 00-00-00-00-00-00
Source IP Address: 58.47.141.26 : 6000
Destination IP Address: 144.165.210.250 : 2967
Protocol: TCP
TCP flags: S
Time-to-live: 100
Actually, it explained in the Firewall entry for ENS with the highlight on the logging result, so S is SYN Flood etc.
The rest can be Googled!