
P-2302R-P1 Series User’s Guide
210
Chapter 20 Logs
20.1.2 Syslog Logs
There are two types of syslog: event logs and traffic logs. The device generates an event log
when a system event occurs, for example, when a user logs in or the device is under attack.
The device generates a traffic log when a "session" is terminated. A traffic log summarizes the
session's type, when it started and stopped the amount of traffic that was sent and received and
so on. An external log analyzer can reconstruct and analyze the traffic flowing through the
device after collecting the traffic logs.
The following table shows RFC-2408 ISAKMP payload types that the log displays. Please
refer to the RFC for detailed information on each type.
Table 85
Syslog Logs
LOG MESSAGE
DESCRIPTION
Event Log: <Facility*8 + Severity>Mon dd
hr:mm:ss hostname
src="<srcIP:srcPort>"
dst="<dstIP:dstPort>" msg="<msg>"
note="<note>" devID="<mac address>"
cat="<category>"
This message is sent by the system ("RAS" displays as the
system name if you haven’t configured one) when the router
generates a syslog. The facility is defined in the
Log
Settings
screen. The severity is the log’s syslog class. The
definition of messages and notes are defined in the various
log charts throughout this appendix. The “devID” is the MAC
address of the router’s LAN port. The “cat” is the same as
the category in the router’s logs.
Traffic Log: <Facility*8 + Severity>Mon
dd hr:mm:ss hostname
src="<srcIP:srcPort>"
dst="<dstIP:dstPort>" msg="Traffic Log"
note="Traffic Log" devID="<mac
address>" cat="Traffic Log"
duration=seconds sent=sentBytes
rcvd=receiveBytes dir="<from:to>"
protoID=IPProtocolID
proto="serviceName" trans="IPSec/
Normal"
This message is sent by the device when the connection
(session) is closed. The facility is defined in the Log
Settings screen. The severity is the traffic log type. The
message and note always display "Traffic Log". The "proto"
field lists the service name. The "dir" field lists the incoming
and outgoing interfaces ("LAN:LAN", "LAN:WAN",
"LAN:DEV" for example).
Table 86
RFC-2408 ISAKMP Payload Types
LOG DISPLAY
PAYLOAD TYPE
SA
Security Association
PROP
Proposal
TRANS
Transform
KE
Key Exchange
ID
Identification
CER
Certificate
CER_REQ
Certificate Request
HASH
Hash
SIG
Signature
NONCE
Nonce
NOTFY
Notification
Summary of Contents for P-2302R-P1 Series
Page 1: ...P 2302R P1 Series VoIP ATA Station Gateway User s Guide Version 3 60 Edition 1 5 2006...
Page 2: ......
Page 5: ...P 2302R P1 Series User s Guide Certifications 5...
Page 10: ...P 2302R P1 Series User s Guide 10 Customer Support...
Page 38: ...P 2302R P1 Series User s Guide 38 Chapter 1 Introducing the ZyXEL Device...
Page 46: ...P 2302R P1 Series User s Guide 46 Chapter 2 Introducing the Web Configurator...
Page 106: ...P 2302R P1 Series User s Guide 106 Chapter 7 LAN...
Page 125: ...P 2302R P1 Series User s Guide Chapter 9 SIP 125 Figure 60 VoIP SIP SIP Settings Advanced...
Page 130: ...P 2302R P1 Series User s Guide 130 Chapter 9 SIP...
Page 140: ...P 2302R P1 Series User s Guide 140 Chapter 10 Phone...
Page 146: ...P 2302R P1 Series User s Guide 146 Chapter 11 Phone Book...
Page 160: ...P 2302R P1 Series User s Guide 160 Chapter 14 Content Filter...
Page 174: ...P 2302R P1 Series User s Guide 174 Chapter 15 Bandwidth MGMT...
Page 184: ...P 2302R P1 Series User s Guide 184 Chapter 17 Static Route...
Page 208: ...P 2302R P1 Series User s Guide 208 Chapter 19 System...
Page 224: ...P 2302R P1 Series User s Guide 224 Chapter 20 Logs...
Page 234: ...P 2302R P1 Series User s Guide 234 Appendix A Product Specifications...
Page 256: ...P 2302R P1 Series User s Guide 256 Appendix C IP Subnetting...
Page 258: ...P 2302R P1 Series User s Guide 258 Appendix D SIP Passthrough...
Page 288: ...P 2302R P1 Series User s Guide 288 Appendix G Services...