
Chapter 21 Logs
Table 94 Access Control Logs
LOG MESSAGE | DESCRIPTION |
Firewall default policy: [ TCP | Attempted TCP/UDP/IGMP/ESP/GRE/OSPF access |
UDP IGMP ESP GRE OSPF ] | matched the default policy and was blocked or |
<Packet Direction> | forwarded according to the default policy’s |
| setting. |
|
|
Firewall rule [NOT] match:[ TCP | Attempted TCP/UDP/IGMP/ESP/GRE/OSPF access |
UDP IGMP ESP GRE OSPF | matched (or did not match) a configured firewall |
] <Packet Direction>, <rule:%d> | rule (denoted by its number) and was blocked or |
| forwarded according to the rule. |
|
|
Triangle route packet forwarded: | The firewall allowed a triangle route session to |
[ TCP UDP IGMP ESP GRE | pass through. |
OSPF ] |
|
Packet without a NAT table entry | The router blocked a packet that didn't have a |
blocked: [ TCP UDP IGMP | corresponding NAT table entry. |
ESP GRE OSPF ] |
|
Router sent blocked web site | The router sent a message to notify a user that |
message: TCP | the router blocked access to a web site that the |
| user requested. |
|
|
Table 95 TCP Reset Logs
LOG MESSAGE | DESCRIPTION |
Under SYN flood attack, | The router sent a TCP reset packet when a host was |
sent TCP RST | under a SYN flood attack (the TCP incomplete count is per |
| destination host.) |
|
|
Exceed TCP MAX | The router sent a TCP reset packet when the number of |
incomplete, sent TCP RST | TCP incomplete connections exceeded the user configured |
| threshold. (the TCP incomplete count is per destination |
| host.) Note: Refer to TCP Maximum Incomplete in the |
| Firewall Attack Alerts screen. |
|
|
Peer TCP state out of | The router sent a TCP reset packet when a TCP |
order, sent TCP RST | connection state was out of order.Note: The firewall refers |
| to RFC793 Figure 6 to check the TCP state. |
|
|
Firewall session time | The router sent a TCP reset packet when a dynamic |
out, sent TCP RST | firewall session timed out.Default timeout values:ICMP |
| idle timeout (s): 60UDP idle timeout (s): 60TCP |
| connection (three way handshaking) timeout (s): 30TCP |
| |
| (s): 3600 |
|
|
308 |
| |
| ||
|
|
|