ZyWALL 35 User’s Guide
Appendix Q Log Descriptions
677
Table 36
Access Control Logs
LOG MESSAGE
DESCRIPTION
Firewall default policy: [ TCP |
UDP | IGMP | ESP | GRE | OSPF ]
<Packet Direction>
Attempted TCP/UDP/IGMP/ESP/GRE/OSPF access
matched the default policy and was blocked or forwarded
according to the default policy’s setting.
Firewall rule [NOT] match:[ TCP
| UDP | IGMP | ESP | GRE | OSPF ]
<Packet Direction>, <rule:%d>
Attempted TCP/UDP/IGMP/ESP/GRE/OSPF access
matched (or did not match) a configured firewall rule
(denoted by its number) and was blocked or forwarded
according to the rule.
Triangle route packet forwarded:
[ TCP | UDP | IGMP | ESP | GRE |
OSPF ]
The firewall allowed a triangle route session to pass
through.
Packet without a NAT table entry
blocked: [ TCP | UDP | IGMP | ESP
| GRE | OSPF ]
The router blocked a packet that didn't have a
corresponding NAT table entry.
Router sent blocked web site
message: TCP
The router sent a message to notify a user that the router
blocked access to a web site that the user requested.
Exceed maximun sessions per host (%d).
The device blocked a session because the host's
connections exceeded the maximum sessions per host.
Firewall allowed a packet that matched a
NAT session: [ TCP | UDP ]
A packet from the WAN (TCP or UDP) matched a cone
NAT session and the device forwarded it to the LAN.
Table 37
TCP Reset Logs
LOG MESSAGE
DESCRIPTION
Under SYN flood attack,
sent TCP RST
The router sent a TCP reset packet when a host was under a SYN
flood attack (the TCP incomplete count is per destination host.)
Exceed TCP MAX
incomplete, sent TCP RST
The router sent a TCP reset packet when the number of TCP
incomplete connections exceeded the user configured threshold.
(the TCP incomplete count is per destination host.) Note: Refer to
TCP Maximum Incomplete
in the
Firewall Attack Alerts
screen.
Peer TCP state out of
order, sent TCP RST
The router sent a TCP reset packet when a TCP connection state
was out of order.Note: The firewall refers to RFC793 Figure 6 to
check the TCP state.
Firewall session time
out, sent TCP RST
The router sent a TCP reset packet when a dynamic firewall
session timed out.
The default timeout values are as follows:
ICMP idle timeout: 3 minutes
UDP idle timeout: 3 minutes
TCP connection (three way handshaking) timeout: 270 seconds
TCP FIN-wait timeout: 2 MSL (Maximum Segment Lifetime set in
the TCP header).
TCP idle (established) timeout (s): 150 minutes
TCP reset timeout: 10 seconds
Содержание ZyXEL ZyWALL 35
Страница 1: ...ZyWALL 35 Internet Security Appliance User s Guide Version 3 64 3 2005 ...
Страница 2: ......
Страница 38: ...ZyWALL 35 User s Guide 36 ...
Страница 46: ...ZyWALL 35 User s Guide 44 ...
Страница 74: ...ZyWALL 35 User s Guide 72 Chapter 2 Introducing the Web Configurator ...
Страница 90: ...ZyWALL 35 User s Guide 88 Chapter 3 Wizard Setup ...
Страница 100: ...ZyWALL 35 User s Guide 98 Chapter 4 LAN Screens ...
Страница 106: ...ZyWALL 35 User s Guide 104 Chapter 5 Bridge Screens ...
Страница 128: ...ZyWALL 35 User s Guide 126 Chapter 6 Wireless LAN ...
Страница 135: ...ZyWALL 35 User s Guide Chapter 7 WAN Screens 133 Figure 47 General ...
Страница 152: ...ZyWALL 35 User s Guide 150 Chapter 7 WAN Screens Figure 57 Dial Backup Setup ...
Страница 158: ...ZyWALL 35 User s Guide 156 Chapter 7 WAN Screens ...
Страница 166: ...ZyWALL 35 User s Guide 164 Chapter 8 DMZ Screens ...
Страница 188: ...ZyWALL 35 User s Guide 186 Chapter 10 Firewall Screens Figure 75 Creating Editing A Firewall Rule ...
Страница 193: ...ZyWALL 35 User s Guide Chapter 10 Firewall Screens 191 Figure 80 My Service Rule Configuration ...
Страница 234: ...ZyWALL 35 User s Guide 232 Chapter 13 Introduction to IPSec ...
Страница 246: ...ZyWALL 35 User s Guide 244 Chapter 14 VPN Screens Figure 116 VPN Rules IKE Gateway Policy Edit ...
Страница 252: ...ZyWALL 35 User s Guide 250 Chapter 14 VPN Screens Figure 117 VPN Rules IKE Network Policy Edit ...
Страница 275: ...ZyWALL 35 User s Guide Chapter 15 Certificates 273 Figure 129 My Certificate Details ...
Страница 294: ...ZyWALL 35 User s Guide 292 Chapter 16 Authentication Server Figure 140 Local User Database ...
Страница 314: ...ZyWALL 35 User s Guide 312 Chapter 17 Network Address Translation NAT ...
Страница 318: ...ZyWALL 35 User s Guide 316 Chapter 18 Static Route ...
Страница 324: ...ZyWALL 35 User s Guide 322 Chapter 19 Policy Route ...
Страница 340: ...ZyWALL 35 User s Guide 338 Chapter 20 Bandwidth Management ...
Страница 376: ...ZyWALL 35 User s Guide 374 Chapter 22 Remote Management ...
Страница 390: ...ZyWALL 35 User s Guide 388 Chapter 24 Logs Screens Figure 198 Log Settings ...
Страница 413: ...ZyWALL 35 User s Guide Chapter 25 Maintenance 411 Figure 220 Restart Screen ...
Страница 414: ...ZyWALL 35 User s Guide 412 Chapter 25 Maintenance ...
Страница 440: ...ZyWALL 35 User s Guide 438 Chapter 28 WAN and Dial Backup Setup ...
Страница 456: ...ZyWALL 35 User s Guide 454 Chapter 31 DMZ Setup ...
Страница 460: ...ZyWALL 35 User s Guide 458 Chapter 32 Route Setup ...
Страница 470: ...ZyWALL 35 User s Guide 468 Chapter 33 Remote Node Setup ...
Страница 522: ...ZyWALL 35 User s Guide 520 Chapter 39 System Information Diagnosis ...
Страница 538: ...ZyWALL 35 User s Guide 536 Chapter 40 Firmware and Configuration File Maintenance ...
Страница 550: ...ZyWALL 35 User s Guide 548 Chapter 42 Remote Management ...
Страница 558: ...ZyWALL 35 User s Guide 556 Chapter 43 IP Policy Routing ...
Страница 574: ...ZyWALL 35 User s Guide 572 Chapter 45 Troubleshooting Figure 364 Java Sun ...
Страница 602: ...ZyWALL 35 User s Guide 600 Appendix C IP Subnetting ...
Страница 608: ...ZyWALL 35 User s Guide 606 Appendix E PPTP ...
Страница 626: ...ZyWALL 35 User s Guide 624 Appendix G Triangle Route ...
Страница 656: ...ZyWALL 35 User s Guide 654 Appendix J Importing Certificates ...
Страница 658: ...ZyWALL 35 User s Guide 656 Appendix K Command Interpreter ...
Страница 664: ...ZyWALL 35 User s Guide 662 Appendix L Firewall Commands ...
Страница 668: ...ZyWALL 35 User s Guide 666 Appendix M NetBIOS Filter Commands ...
Страница 674: ...ZyWALL 35 User s Guide 672 Appendix O Brute Force Password Guessing Protection ...
Страница 696: ...ZyWALL 35 User s Guide 694 Appendix Q Log Descriptions ...