Chapter11. Logging
youcan select allowed, un-NAT:ed packets only.
IP Address Selection
Youcan limit the selection by specifying certain IP addresses.
Inthese fields, enter a single IP address (e. g., 10.3.27.3), a range of IP addresses (e. g., 10.3.27.1-10.3.28.254), an
IPaddress followed by a netmask (e. g.,10.3.27.0/24), a combination of these, or nothing at all. If a field is empty,
allIP addresses are selected.
Ifyou want to study all traffic except the one to or from a specific computer or group of computers, enter the IP
address(es)here and mark the "not this address" box.
Theselection can be modified by the control boxes under the fields A and B:
Asrc Packetsfrom the IP address in field A matches. Field B is ignored.
Adst Packetsto the IP address in field A matches. Field B is ignored.
Aany Packetsto or from the IP address in field A matches. Field B is ignored.
Ato B Packetsfrom A to B matches.
Bto A Packetsfrom B to A matches.
BetweenA&B Packetsfrom A to B, or from B to A, matches.
notthis combination Packetsthat do not match the given combination of A and B are shown in
thelog.
Ifyou, for example, want to study all packets to or from 10.3.27.18, except those to the file server 10.3.27.2, you
shouldfill in the form like this:
Protocol/Port Selection
Youcan limit the selection by specifying certain protocols.

All IP protocols

Norestriction regarding protocols.

TCP/UDP

Whenselecting TCP or UDP, you can choose all packets or packets to certain ports only.
Inthese fields, you can enter a single port number (32), a range of port numbers (1-1023), alist of port numbers and
rangesseparated by commas (53, 1024-65535) or nothing at all. If the field is empty, any port will match. See
appendixG, Lists of ports, ICMP and protocols, for more information on port numbers.
Ifyou want to study all traffic except the one to or from a specific port or group of ports, enter the port number(s)
hereand mark the "not this port" box.
Theselection can be modified by the control boxes under the fields A and B:
Asrc Packetsfrom the port number in field A matches. Field B is ignored.
Adst Packetsto the port number in field A matches. Field B is ignored.
Aany Packetsto or from the port number in field A matches. Field B is ignored.
99