
into <sgrp> and source <src> into <ssrc>.
Explanation
Got IGMP Query.
Gateway Action
allow
Recommended Action
None.
Revision
1
Parameters
if
rip
igmpver
grp
src
sgrp
ssrc
name
action
2.13.10. bad_src (ID: 04200011)
Default Severity
WARNING
Log Message
Rule <name> drops multicast sender <src> (SAT'ed into <sats>) in
group <grp> (SAT'ed into <satg>) specific IGMP Query at interface
<iface>.
Explanation
This is most likely a faulty IGMP configuration, but may also indicate
faulty software on the network. Under special circumstances this could
be an active attempt to scan the network for information.
Gateway Action
drop
Recommended Action
Specifically check your IGMP ruleset for incorrect SAT information
(IGMP support requires at least one "REPORT" (Member Report) rule
and one matching "QUERY" rule). Make sure both multicast groups
and source addresses map one-to-one between Member Reports and
Queries. Finally check the network for for other anomalies that could
indicate broken equipment or installed "spyware".
Revision
1
Parameters
name
src
grp
sats
satg
iface
2.13.11. igmp_report_received (ID: 04200012)
Default Severity
NOTICE
Log Message
Rule <name> <action> IGMP Member Report concerning group
<grp> and source <src> at interface <if> from host <hip>. Group
<grp> is translated into <sgrp> and source <src> into <ssrc>
Explanation
Got IGMP Report.
2.13.10. bad_src (ID: 04200011)
Chapter 2. Log Message Reference
174
Summary of Contents for NetDefend SOHO DFL-160
Page 20: ...List of Tables 1 Abbreviations 23 20 ...
Page 21: ...List of Examples 1 Log Message Parameters 22 2 Conditional Log Message Parameters 22 21 ...
Page 31: ...1 3 Severity levels Chapter 1 Introduction 31 ...
Page 356: ...2 33 53 sent_sslalert ID 03700511 Chapter 2 Log Message Reference 356 ...