INS_RL1000GW_REV– 15 Jul 2016 PAGE 53
INSTALLATION AND OPERATION MANUAL
RL1000GW
TECH SUPPORT: 1.888.678.9427
1. Example for violation type “no rule configured”
- Local0.Error 172.18.212.183 May 12 11:52:54 SW RLGE2FE16R firewall
- |ID=79|T=2014-05-12,11:52:54
|S=E|SG=3500|SRC=172.18.212.50:52011|DST=172.18.212.46:2404|LEN=62|TTL=128|PROTO=iec104|MSG=[0x100]
[45,0]:FW RULE - no rule configured|
2. Example for violation type “protocol type mismatch”
- 05-12-2014 16:53:40 Local0.Alert 172.18.212.183 May 12 11:52:59 SW RLGE2FE16R firewall
- |ID=80|T=2014-05-12,11:52:59
|S=A|SG=3500|SRC=172.18.212.50:52011|DST=172.18.212.46:2404|LEN=56|TTL=128|PROTO=iec104|MSG=[0x101]
[45,0]:FW PROTOCOL protcol type missmatch| (170 bytes)
Firewall Serial SCADA Protocols
The following will describe the ComNet structure of syslog mssages generated for firewall of IEC
101, DNP3 RTU, MODBUS RTU.
IP=IP _ ADDR|SLOT=SLOT _ NUMBER|PORT=PORT _ NUMBER|DIR=DATA _ MSG _ DIR|LEN=DATA _ MSG _
LEN|PROTO=PROTOCOL _ NAME|MSG=VIOLATION _ DESCR|