53
The next field indicates what happened to the packet:
•
drop: The packet was discarded
•
rej: The packet was discarded and the sender was notified (with an
ICMP packet or a TCP reset)
•
fake: SX-GATE replied with a faked answer
•
acc: the packet was accepted. Normally accepted packets are not
logged, so it is unlikely that you will see this value
In brackets the reason is stated, why the packet was logged. The value "restricted"
indicates, that the current firewall policy does not allow this kind of connection.
However it is possible to add a firewall rule to grant access.
Among others, the following fields show the name of the interface through which
the packet was received and through which it would have been sent. Next are
the layer 3 protocol of the packet and its source and destination IPs. For TCP
and UDP, the respective source port and destination port (DPT=) is listed. For
ICMP packets the ICMP type and code can be found in the port columns, which
indicate the message type. For TCP connections the TCP flags are shown. The
last column contains the MAC address of the sender.
IDS/IPS
Shows alerts logged by the Intrusion Detection and Prevention System (IDS/IPS).
The IDS/IPS examines the contents of IP packets and compares them with a
signature database.
Besides date and time the log will show you what happened to the packet. The
text "Drop" indicates that the corresponding IP packet has been discarded by the
IPS instance running within the firewall, whereas "wDrop" indicates that the IDS
logged the packet. In contrast to the IPS, the IDS is a passive component on the
monitor port of a switch.
The reference is the combination of module ID (usually 1), rule ID and revision
number, separated by colons (e.g. 1:2345678:9). You need the rule ID (here:
"2345678") to disable a rule in the IDS/IPS configuration.
The next columns contain the rule name and a classification, indicating the type
of the event. The priority indicates if it's a critical problem (priority 1) or less critical
(priorities 2, 3 or 4). The final columns contain the layer 3 protocol, source and
destination IP and the ports.
IPSec
This file contains the messages logged by SX-GATE's IPSec VPN server.
Clustering
This logfile records the actions of the cluster.