ZyWALL 2 Series User’s Guide

 

 

 

 

Chart O-6 Access Logs

 

 

 

 

 

 

 

LOG MESSAGE

 

DESCRIPTION

 

 

 

 

 

 

 

 

Packet without a NAT

The router blocked a packet that did not have a corresponding

 

 

table entry blocked

SUA/NAT table entry.

 

 

Out of order TCP

The router blocked a TCP handshake packet that came out of the

 

 

handshake packet

proper order

 

 

blocked

 

 

 

 

 

Drop unsupported/out-

The ZyWALL generates this log after it drops an ICMP packet due to

 

 

of-order ICMP

one of the following two reasons:

 

 

 

 

1. The ZyWALL does not support the ICMP packet's protocol.

 

 

 

 

2. The ICMP packet is an echo reply for which there was no

 

 

 

 

corresponding echo request.

 

 

 

 

 

 

 

 

Router sent ICMP

The router sent an ICMP response packet. This packet automatically

 

 

response packet

bypasses the firewall. See the section on ICMP messages for type

 

 

(type:%d, code:%d)

and code details.

 

 

 

 

 

 

 

 

Chart O-7 ACL Setting Notes

 

 

 

 

 

 

ACL SET

DIRECTION

 

DESCRIPTION

 

 

NUMBER

 

 

 

 

 

1

LAN to WAN

 

ACL set 1 for packets traveling from the LAN to the WAN.

 

 

2

WAN to LAN

 

ACL set 2 for packets traveling from the WAN to the LAN.

 

 

7

LAN to

 

ACL set 7 for packets traveling from the LAN to the LAN or the

 

 

 

LAN/ZyWALL

 

ZyWALL.

 

 

8

WAN to

 

ACL set 8 for packets traveling from the WAN to the WAN or the

 

 

 

WAN/ZyWALL

 

ZyWALL.

 

 

 

Chart O-8 ICMP Notes

 

 

 

TYPE

CODE

DESCRIPTION

 

 

 

0

 

Echo Reply

 

0

Echo reply message

Log Descriptions

O-9