Chapter 20 Logs

[Rule] NAT — name of the traffic rule which has been used (a rule by which the traffic was allowed or denied).

[Service] HTTP — name of a corresponding application layer service (recognized by destination port).

If the corresponding service is not defined in WinRoute (refer to chapter 12.3), the [Service] item is missing in the log.

[User] james name of the user connected to the firewall from a host which partici- pates in the traffic.

If no user is currently connected from the corresponding host, the [User] item is missing in the log.

[Connection] TCP 192.168.1.140:1193 -> hit.top.com:80 — protocol, source IP address and port, destination IP address and port. If an appropriate log is found in the DNS Forwarder cache (see chapter 5.3), the host’s DNS name is displayed instead of its IP address. If the log is not found in the cache, the name is not detected (such DNS requests would slow WinRoute down).

[Duration] 121 sec — duration of the connection (in seconds)

[Bytes] 1575/1290/2865 — number of bytes transferred during this connection (transmitted /accepted /total).

[Packets] 5/9/14 — number of packets transferred through this connection (transmitted/accepted/total).

20.6 Debug Log

Debug (debug information) is a special log which can be used to monitor certain kinds of information, especially for problem-solving. Too much information could be confusing and impractical if displayed all at the same time. Usually, you only need to display information relating to a particular service or function. In addition, displaying too much information slows WinRoute’s performance. Therefore, it is strongly recommended to monitor an essential part of information and during the shortest possible period only.

20.7 Dial Log

Data about dialing and hanging up the dial-up lines, and about time spent on-line.

The following items (events) can be reported in the Dial log:

1.Manual connection (from the Administration Console — see chapter 5.1 or right from the operating system)

286

Page 286
Image 286
Kerio Tech Firewall6 manual Debug Log, Dial Log, 286