Traffic log message format
Traffic log messages record each connection made to a DFL-1000 interface. Each message records the
date and time at which the connection was made, the source and destination address of the connection,
and whether the connection was accepted or denied by the firewall.
Traffic log messages are created if you select one or more of the following log settings:
•
Log All Internal Traffic to Firewall
•
Log All External Traffic to Firewall
•
Log All DMZ Traffic to Firewall
Traffic log messages are also created when a policy that is set to log traffic processes a connection.
Sample Traffic Log messages:
describes the traffic log message format.
Traffic log message format
Description Format
Example
Maximum
Length
Date and time the log message was
recorded
YYYY MMM DD
hh:mm:ss
2002 Mar 12
05:03:45
15 bytes
Protocol
TCP
,
UDP
, or
ICMP
TCP
5 bytes
Source IP address and port number
ipaddress:port
192.168.1.98:443
21 bytes
Destination IP and port
ipaddress:port
192.168.1.23:1199
21 bytes
TCP flag (optional)
FIN
or
SYN
3 bytes
Length of traffic packet
LEN=length
LEN=40
8 bytes
Action
ACCEPT
or
DENY
ACCEPT
6 bytes
Event log message format
Event log messages record changes made to the DFL-1000 configuration using the web-based manager.
Each message records the date and time at which the change was made, a description of the change,
and the IP address of the management computer from which the change was made.
Event log messages are created if you select the Log All Event setting.
DFL-1000 User’s Manual
86