Table 98 TCP Reset Logs (continued)
LOG MESSAGE
Firewall session time
out, sent TCP RST
Exceed MAX incomplete,
sent TCP RST
Access block, sent TCP
RST
Table 99 Packet Filter Logs
LOG MESSAGE
[ TCP | UDP | ICMP | IGMP |
Generic ] packet filter
matched (set: %d, rule: %d)
or type and code details, see
F
Table 100 ICMP Logs
LOG MESSAGE
Firewall default policy: ICMP
<Packet Direction>, <type:%d>,
<code:%d>
Firewall rule [NOT] match: ICMP
<Packet Direction>, <rule:%d>,
<type:%d>, <code:%d>
Triangle route packet forwarded:
ICMP
User's Guide
DESCRIPTION
The router sent a TCP reset packet when a dynamic
firewall session timed out.
The default timeout values are as follows:
ICMP idle timeout: 3 minutes
UDP idle timeout: 3 minutes
TCP connection (three way handshaking) timeout: 270
seconds
TCP FIN-wait timeout: 2 MSL (Maximum Segment
Lifetime set in the TCP header).
TCP idle (established) timeout (s): 150 minutes
TCP reset timeout: 10 seconds
The router sent a TCP reset packet when the number of
incomplete connections (TCP and UDP) exceeded the
user-configured threshold. (Incomplete count is for all
TCP and UDP connections through the firewall.)Note:
When the number of incomplete connections (TCP + UDP)
> "Maximum Incomplete High", the router sends TCP RST
packets for TCP connections and destroys TOS (firewall
dynamic sessions) until incomplete connections <
"Maximum Incomplete Low".
The router sends a TCP RST packet and generates this log
if you turn on the firewall TCP reset mechanism (via CI
command:
sys firewall tcprst
DESCRIPTION
Attempted access matched a configured filter rule
(denoted by its set and rule number) and was blocked
or forwarded according to the rule.
Table 106 on page
239.
DESCRIPTION
ICMP access matched the default policy and was
blocked or forwarded according to the user's
setting.
ICMP access matched (or didn't match) a firewall
rule (denoted by its number) and was blocked or
forwarded according to the rule.
The firewall allowed a triangle route session to
pass through.
Chapter 19 The Logs Screens
).
235