Wanguard 6.2 User Guide
Configuration » General Settings » Graphs & Storage
granularity IP graphs.
Decoders
represent internal functions that differentiate and classify the underlying protocols of each packet
and flow. Each enabled decoder increases the size of IP graph, top and accounting data, and causes a small
performance penalty on Packet Sensor and Packet Filter. It is recommended to enable only the decoders you are
interested in.
You can define your own decoders in Configuration » General Settings » Custom Decoders. Default decoders:
Decoder
Description
TOTAL
Always enabled, matches all IP packets & flows.
TCP
Matches TCP traffic.
TCP+SYN
Matches TCP traffic with SYN flag set and ACK unset. Flow Sensor counts one packet per flow.
UDP
Matches UDP traffic.
ICMP
Matches ICMP traffic.
OTHER
Matches IP protocols that differ from TCP, UDP and ICMP.
BAD
Matches TCP or UDP port set to 0, or IP protocol set to 0.
FLOWS
Matches flow records and replaces packets/s with flows/s. Works only with Flow Sensor.
FLOW+SYN
Matches flow records with SYN flag set. Flow Sensor counts all packets per flow.
FRAGMENT
Matches fragmented IP packets. Works only with Packet Sensor.
TCP-NULL
Matches TCP traffic without TCP flags, indicative of reconnaissance sweeps.
TCP+RST
Matches TCP traffic with RST flag set.
TCP+ACK
Matches TCP traffic with SYN flag unset and ACK set.
TCP+SYNACK
Matches TCP traffic with SYN flag set and ACK flag set.
HTTP
Matches TCP traffic on source or destination port 80.
HTTPS
Matches TCP traffic on source or destination port 443.
Matches TCP traffic on source or destination ports 25,110,143,465,585,587,993,995.
DNS
Matches UDP traffic on source or destination port 53.
SIP
Matches TCP or UDP traffic on source or destination port 5060.
IPSEC
Matches IP traffic on IP protocol 50 or 51.
WWW
Matches TCP traffic on source or destination ports 80, 443.
SSH
Matches TCP traffic on source or destination port 22.
NTP
Matches UDP traffic on source or destination port 123.
SNMP
Matches UDP traffic on source or destination ports 161, 163.
RDP
Matches TCP or UDP traffic on source or destination port 3389.
YOUTUBE
Matches IP traffic going or coming from Youtube AS 43515, 36561, or from Youtube subnets.
NETFLIX
Matches IP traffic going or coming from Netflix AS 55095, 40027, 2906, or from Netflix subnets.
HULU
Matches IP traffic going or coming from Hulu AS 23286, or from Hulu subnets.
Matches IP traffic going or coming from Facebook AS 54115, 32934, or from Facebook subnets.
Consolidation functions
build consolidated values for Round Robin Archives. If you are interested in traffic
spikes, check MAXIMUM. If you are interested in average values, check AVERAGE. For low traffic values, check
MINIMUM.
- 21 -
Summary of Contents for wanguard 6.2
Page 1: ......