Administrator’s Handbook
100
Access-related Log Messages
1. permitted:
This log-message is generated whenever a packet is allowed to traverse
router-interfaces or allowed to access the router itself.
2. attempt:
This log-message is generated whenever a packet attempts to traverse
router-interfaces or attempts to access the router itself.
3. dropped - violation of security
policy:
This log-message is generated whenever a packet, traversing the router or
destined to the router itself, is dropped by the firewall because it violates
the expected conditions.
4. dropped - invalid checksum:
This log-message is generated whenever a packet, traversing the router or
destined to the router itself, is dropped because of invalid IP checksum.
5. dropped - invalid data length:
This log-message is generated whenever a packet, traversing the router or
destined to the router itself, is dropped because the IP length is greater than
the received packet length or if the length is too small for an IP packet.
6. dropped - fragmented packet:
This log-message is generated whenever a packet, traversing the router, is
dropped because it is fragmented, stateful inspection is turned ON on the
packet's transmit or receive interface, and deny-fragment option is enabled.
7. dropped - cannot fragment:
This log-message is generated whenever a packet traversing the router is
dropped because the packet cannot be sent without fragmentation, but the
do not fragment bit is set.
8. dropped - no route found:
This log-message is generated whenever a packet, traversing the router or
destined to the router itself, is dropped because no route is found to for-
ward the packet.
9. dropped - invalid IP version:
This log-message is generated whenever a packet, traversing the router or
destined to the router itself, is dropped because the IP version is not 4.
10. dropped - possible land attack:
This log-message is generated whenever a packet, traversing the router or
destined to the router itself, is dropped because the packet is TCP/UDP
packet and source IP Address and source port equals the destination IP
Address and destination port.
11. TCP SYN flood detected:
This log-message is generated whenever a SYN packet destined to the
router's management interface is dropped because the number of SYN-sent
and SYN-receives exceeds one half the number of allowable connections in
the router.
12. Telnet receive DoS attack -
packets dropped:
This log-message is generated whenever TCP packets destined to the
router's telnet management interface are dropped due to overwhelming
receive data.
13. dropped - reassembly timeout:
This log-message is generated whenever packets, traversing the router or
destined to the router itself, are dropped because of reassembly timeout.
14. dropped - illegal size:
This log-message is generated whenever packets, traversing the router or
destined to the router itself, are dropped during reassembly because of ille-
gal packet size in a fragment.
Содержание NVG595
Страница 1: ...ARRIS NVG595 Fiber Business Gateway ARRIS Embedded Software Version 9 1 2 Administrator s Handbook ...
Страница 10: ...Administrator s Handbook 10 ...
Страница 65: ...65 ...
Страница 68: ...Administrator s Handbook 68 ...
Страница 84: ...Administrator s Handbook 84 The following is an example log portion saved as a TXT file ...
Страница 90: ...Administrator s Handbook 90 ...
Страница 185: ...185 Please visit http www ARRIS com recycle for instructions on recycling ...
Страница 210: ...Administrator s Handbook 210 ...
Страница 220: ...Administrator s Handbook 218 ...
Страница 224: ...Administrator s Handbook 222 ...
Страница 226: ...Administrator s Handbook 224 ...