Example log settings
Selecting what to log
Use the following procedure to configure the type of information recorded in DFL-500 logs.
When running in Transparent mode, the DFL-500 only supports Log All Events.
·
Go to
Log&Report > Log setting
.
·
Select Log All Internal Traffic To Firewall to record all connections to the internal interface.
·
Select Log All External Traffic To Firewall to record all connections to the external interface.
·
Select Log All Events to record all the changes made to the DFL-500 configuration.
·
Select Apply to save your log settings.
Log message formats
The DFL-500 Traffic logs, Event logs, and Attack logs all have their own message format. All of these
message formats are compatible with the WebTrends Enhanced Log Format (WELF).
Use the information in the following sections to interpret DFL-500 log messages:
·
·
·
Traffic log message format
When you select the Log Traffic policy option, traffic logs record sessions that match firewall policies. Each
traffic log message records the date and time at which the session was started, the source and destination
address of the session, and whether the session was accepted or denied by the firewall. Traffic logs do not
record individual packets.
A sample traffic log message contains the following information:
<date> <time> src=<source IP> dst=<destination IP> proto=<destination port>
msg="<protocol>, sport=<source port> <packet type> <action>"
DFL-500 User Manual
104
Содержание DFL-500
Страница 1: ...DFL 500 V2 27 User Manual D Link Systems Inc DFL 500 User Manual 1 ...
Страница 102: ...DFL 500 User Manual 102 ...
Страница 136: ...DFL 500 User Manual 136 ...
Страница 140: ...Registration Register the D Link DFL 500 Office Firewall online at http www dlink com sales reg DFL 500 User Manual 140 ...