Chapter 13: Reviewing and Working with Log Files
IP header length
TTL (time to live)
Source address
Destination address
Source port
Destination port
Details
Working with Log Files
The Firebox continually writes messages to log files on the
WatchGuard Security Event Processor (WSEP). Because
228
Length, in octets, of the IP header for this packet. A
header length that is not equal to 20 indicates that
IP options were present. Default = Hide
The value of the TTL field in the logged packet.
Default = Hide
The source IP address of the logged packet. Default
= Show
The destination IP address of the logged packet.
Default = Show
The source port of the logged packet, UDP or TCP
only.
Default = Show
The destination port of the logged packet, UDP or
TCP only. Default = Show
Additional information appears after the
previously described fields, including data about
IP fragmentation, TCP flag bits, IP options, and
source file and line number when in trace mode. If
WatchGuard logging is in debug or verbose mode,
additional information is reported. In addition, the
type of connection may be displayed in
parentheses. Default = Show
WatchGuard Firebox System
Need help?
Do you have a question about the Firebox X1000 and is the answer not in the manual?