Firewall Trace Output - Digi TransPort WR31 User Manual

Hide thumbs Also See for TransPort WR31:
Table of Contents

Advertisement

Manage networks and connections

Firewall trace output

The log keyword appends output to the firewall trace output. Typically, the last rule in the form
block log break end uses the log keyword to log a summary of all packets not matching one of the
allow rules. The log keyword provides more logging flexibility; see the log action description in
Firewall script rule
Example firewall trace output
Here is example firewall trace output from a firewall rule, showing two logged packets. Output for
the first packet is:
block log break end
----- 5-10-2009 23:12:08 ------
FW LOG Dir: IN Line: 37 Hits: 4730 IFACE: ETH 3
Source IP: 222.45.112.59 Dest IP: 217.34.133.21 ID: 256 TTL: 106
PROTO: TCP (6)
Src Port: 12200 Dst Port: 8118
block log break end
----------
----- 5-10-2009 23:13:15 ------
FW LOG Dir: IN Line: 37 Hits: 4731 IFACE: ETH 3
Source IP: 218.61.22.42 Dest IP: 217.34.133.21 ID: 35372 TTL: 136
PROTO: TCP (6)
Src Port: FTP CTL (21) Dst Port: 16794
block log break end
----------
Next is the time stamp of the blocked packet.
----- 5-10-2009 23:12:08 ------
FW LOG Dir: IN Line: 37 Hits: 4730 IFACE: ETH 3
Source IP: 222.45.112.59 Dest IP: 217.34.133.21 ID: 256 TTL: 106
PROTO: TCP (6)
Src Port: 12200 Dst Port: 8118
Dir is the direction of the packet that was logged, either IN or OUT of the router.
Line is the line number within the firewall rules that caused this packet to be logged.
Hits is the number of packets that have matched this rule.
IFACE is the interface which the packet was logged on.
Source IP is the source IP address of the packet that was logged.
Dest IP is the destination IP address of the packet that was logged.
ID is the ID of the packet, this is taken from the packet header.
TTL is the Time To Live value.
PROTO is the layer 3 protocol of the logged packet.
Src Port is the source TCP or UDP port number of the packet that was logged.
Dst Port is the destination TCP or UDP port number of the packet that was logged.
block log break end is the actual rule that caused the packet to be logged.
Digi TransPort WR Routers User Guide
fields.
View network interface status
781

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents