System Log; Access Logging - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

A

System Log

Contents

Access logging

Creating custom log rules
Rate limiting
Administrative access log messages
Boot log messages
Access logging
It is possible to log any traffic that arrives at or traverses the UTM Firewall appliance. The only logging that
is enabled by default is to take note of dropped packets. While it is possible to specifically log exactly which
rule led to such a drop, this is not configured by default. All rules in the default security policy drop packets.
They never reject them. That is, the packets are simply ignored, and have no responses at all returned to
the sender. It is possible to configure reject rules if so desired.
All traffic logging performed on the appliance creates entries in the syslog
(/var/log/messages or external syslog server) of the following format:
<Date/Time> klogd: <prefix> IN=<incoming interface> OUT=<outgoing interface>
MAC=<dst/src MAC addresses> SRC=<source IP> DST=<destination IP> SPT=<source port>
DPT=<destination port> <additional packet info>
Where:
<prefix> if non-empty, hints at cause for log entry
<incoming interface> empty, or one of eth0, eth1 or similar
<outgoing interface> as per incoming interface
<dst/src MAC addresses> MAC addresses associated with the packet
<source IP> packet claims it came from this IP address
<destination IP> packet claims it should go to this IP address
<source port> packet claims it came from this TCP port
<destination port> packet wants to go to this TCP port
Depending on the type of packet and logging performed some of the fields may not appear.
Commonly used interfaces are:
eth0 — the LAN port
eth1 — the WAN/Internet port
pppX — such as ppp0 or ppp1, a PPP session
IPSecX — such as IPSec0, an IPSec interface
The firewall rules deny all packets arriving from the WAN port by default. There are a few ports open to deal
with traffic such as DHCP, VPN services, and similar traffic. Any traffic that does not match the exceptions
is dropped.
McAfee UTM Firewall 4.0.4 Administration Guide
373

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents