
Default Severity
NOTICE
Log Message
Found
<blacklisted_host>
in
blacklist.
Triggered
rule
<rule>,
description: <description>. Protocol: <proto>, IP: <ip>, Port: <port>.
Explanation
A blacklist entry was added which matched the IP address of this
connection. Thus it was closed accordingly.
Gateway Action
close
Recommended Action
Investigate threshold or IntrusionDetection rules that could have
triggered dynamic blacklisting.
Revision
1
Parameters
blacklisted_host
rule
description
ip
proto
port
2.6.5. packet_blacklisted (ID: 04600005)
Default Severity
NOTICE
Log Message
Found
<blacklisted_host>
in
blacklist.
Triggered
rule
<rule>,
description: <description>. Protocol: <proto>, IP: <ip>, Port: <port>.
Explanation
A blacklist entry was added which matched the IP address of this
packet. Thus it was dropped accordingly.
Gateway Action
drop
Recommended Action
Investigate threshold or IntrusionDetection rules that could have
triggered dynamic blacklisting.
Revision
1
Parameters
blacklisted_host
rule
description
ip
proto
port
2.6.6. packet_blacklisted (ID: 04600006)
Default Severity
NOTICE
Log Message
Found source in blacklist. Triggered rule <rule>, description:
<description>. Protocol: <proto>, IP: <ip>, Port: <port>.
Explanation
A blacklist entry was added which matched the IP address of this
packet. Thus it was dropped accordingly.
Gateway Action
drop
Recommended Action
Investigate threshold or IntrusionDetection rules that could have
2.6.5. packet_blacklisted (ID:
04600005)
Chapter 2. Log Message Reference
158
Содержание DFL- 860
Страница 25: ...List of Tables 1 Abbreviations 28 25 ...
Страница 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26 ...
Страница 36: ...1 3 Severity levels Chapter 1 Introduction 36 ...
Страница 156: ...Recommended Action None Revision 1 2 5 7 unsynced_databases ID 05000008 Chapter 2 Log Message Reference 156 ...
Страница 173: ...Context Parameters Packet Buffer 2 9 14 route_collision ID 00700015 Chapter 2 Log Message Reference 173 ...
Страница 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195 ...
Страница 240: ...Revision 1 Parameters iface linkspeed duplex 2 20 3 ifacemon_status_bad ID 03900004 Chapter 2 Log Message Reference 240 ...
Страница 309: ...Context Parameters Rule Name Packet Buffer 2 24 3 ip_rsv_flag_set ID 01600003 Chapter 2 Log Message Reference 309 ...
Страница 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409 ...
Страница 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476 ...