ZyXEL Communications Vantage Report User Manual page 667

User guide
Hide thumbs Also See for Vantage Report:
Table of Contents

Advertisement

Table 317 AS Directions for Single WAN Devices
FROM\TO
LAN
WAN
DMZ
WLAN
Syslog Logs
There are two types of syslog: event logs and traffic logs. The device generates an
event log when a system event occurs, for example, when a user logs in or the
device is under attack. The device generates a traffic log when a "session" is
terminated. A traffic log summarizes the session's type, when it started and
stopped the amount of traffic that was sent and received and so on. An external
log analyzer can reconstruct and analyze the traffic flowing through the device
after collecting the traffic logs.
Table 318 Syslog Logs
LOG MESSAGE
Event Log: <Facility*8 +
Severity>Mon dd hr:mm:ss
hostname src="<srcIP:srcPort>"
dst="<dstIP:dstPort>"
msg="<msg>" note="<note>"
devID="<mac address>"
cat="<category>"
Traffic Log: <Facility*8 +
Severity>Mon dd hr:mm:ss
hostname src="<srcIP:srcPort>"
dst="<dstIP:dstPort>"
msg="Traffic Log"
note="Traffic Log" devID="<mac
address>" cat="Traffic Log"
duration=seconds
sent=sentBytes
rcvd=receiveBytes
dir="<from:to>"
protoID=IPProtocolID
proto="serviceName"
trans="IPSec/Normal"
Vantage Report User's Guide
LAN
WAN
(L to L)
(L to W)
(W to L)
(W to W)
(D to L)
(D to W)
(WL to L)
(WL to W)
DESCRIPTION
This message is sent by the system ("RAS" displays
as the system name if you haven't configured one)
when the router generates a syslog. The facility is
defined in the web MAIN MENU, LOGS, Log
Settings page. The severity is the log's syslog
class. The definition of messages and notes are
defined in the other log tables. The "devID" is the
MAC address of the router's LAN port. The "cat" is
the same as the category in the router's logs.
This message is sent by the device when the
connection (session) is closed. The facility is defined
in the Log Settings screen. The severity is the traffic
log type. The message and note always display
"Traffic Log". The "proto" field lists the service
name. The "dir" field lists the incoming and outgoing
interfaces ("LAN:LAN", "LAN:WAN", "LAN:DMZ",
"LAN:DEV" for example).
Appendix C ZyNOS Log Descriptions
DMZ
WLAN
(L to D)
(L to WL)
(W to D)
(W to WL)
(D to D)
(D to WL)
(WL to D)
(WL to WL)
667

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vantage report 3.0Vantage report 2.3

Table of Contents