Conn Events - D-Link DFL-1100 User Manual

Network security firewall
Hide thumbs Also See for DFL-1100:
Table of Contents

Advertisement

CONN events

These events are generated if auditing has been enabled.
One event will be generated when a connection is established. This event will include
information about the protocol, receiving interface, source IP address, source port, destination
interface, destination IP address, and destination port.
Open Example:
Oct 20 2003 09:47:56 gateway EFW: CONN: prio=1 rule=Rule_8 conn=open
connipproto=TCP connrecvif=lan connsrcip=192.168.0.10 connsrcport=3179 conndestif=wan
conndestip=64.7.210.132 conndestport=80
In this line, traffic from 192.168.0.10 on the LAN interface is connecting to 64.7.210.132 on
port 80 on the WAN side of the firewall (internet).
Another event is generated when the connection is closed. The information included in the
event is the same as in the event sent when the connection was opened, with the exception
that statistics regarding sent and received traffic is also included.
Close Example:
Oct 20 2003 09:48:05 gateway EFW: CONN: prio=1 rule=Rule_8 conn=close
connipproto=TCP connrecvif=lan connsrcip=192.168.0.10 connsrcport=3179 conndestif=wan
conndestip=64.7.210.132 conndestport=80 origsent=62 termsent=60
In this line, the connection in the other example is closed.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netdefend dfl-1100

Table of Contents