Example content filtering messages:
2002 Jun 19 23:35:09 src=25.155.34.2 dst=192.168.100.105 proto=http
msg="type=Web-Filter status=BANWORDBLOCK url=www.filtered.com/index.htm"
2002 Jun 12 15:35:02 src=23.11.34.2 dst=192.168.100.105 proto=http
msg="type=Web-Filter status=URLBLOCK url=www.filtered.com/index.htm"
NIDS messages
NIDS log messages record when the NIDS system detects an attack. NIDS messages have the following
format:
<date> <time> src=<source IP> dst=<destination IP> msg="type=<Firewall event
type> attack=<description of intrusion detected>"
Example NIDS messages:
2002 Jun 22 15:23:09 src=65.55.34.2 dst=192.168.100.105 msg="type=Intrusion
attack='Tear Drop Attack' "
2002 Jun 13 12:35:09 src=65.55.34.2 dst=192.168.100.105 msg="type=Intrusion
attack='IP Spoof' "
2002 Jun 11 15:22:09 src=65.55.34.2 dst=192.168.100.105 msg="type=Intrusion
attack='SYN Flood' "
If the policy mode for connections in which attacks are detected is NAT, NIDS log messages contain reverse NAT IP
addresses.
VPN tunnel monitor messages
VPN tunnel monitor log messages record when a VPN tunnel is started and stopped and also when keys are
renegotiated. VPN tunnel monitor messages have the following format:
<date> <time> type=vpn, msg=<description of the VPN tunnel status event>
Example VPN tunnel monitor message:
2002 Jun 19 15:35:09 type=vpn, msg="Initiator: tunnel 172.18.0.1/172.16.0.1 main
mode phase I succeeded"
Attack log message format
Attack logs record attacks intercepted by the DFL-500 NIDS (see
Network Intrusion detection system (NIDS)
).
Each attack log message records the date and time at which the attack was made, the type of attack, and the
source and destination IP addresses of the attack. Attack log messages have the following format:
<date> <time> msg="<Attack type>:<protocol>, src=<source IP>, dst=<destination
IP>"
Example attack log message:
2002 Jun 19 15:35:09 msg="Sync Attack: TCP, src=1.1.1.1 dst=2.2.2.2"
DFL-500 User Manual
106
Содержание DFL-500
Страница 1: ...DFL 500 V2 27 User Manual D Link Systems Inc DFL 500 User Manual 1 ...
Страница 102: ...DFL 500 User Manual 102 ...
Страница 136: ...DFL 500 User Manual 136 ...
Страница 140: ...Registration Register the D Link DFL 500 Office Firewall online at http www dlink com sales reg DFL 500 User Manual 140 ...