18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Field Description<br />

src_burb Specify the destination burb number.<br />

dst_burb Specify the destination burb number.<br />

service Specify the type <strong>of</strong> service (for example, Telnet, FTP, WebProxy, etc.).<br />

Understanding audit messages<br />

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

vpn_l_gw Specify a VPN local gateway using the standard dotted decimal IP version 4 notation with optional<br />

mask bits separated by a slash (/).<br />

vpn_r_gw Specify a VPN remote gateway using the dotted decimal IP version 4 notation with optional mask<br />

bits separated by a slash (/).<br />

When viewing audit messages in the Admin Console, the form may<br />

vary depending on the purpose and content <strong>of</strong> the message. The form<br />

<strong>of</strong> the first two lines is the same for all audit messages, and provides<br />

general information about the process generating or causing the audit.<br />

The third line will vary, but usually includes Type Enforcement<br />

information and possibly some additional information. The other lines<br />

<strong>of</strong> an audit message will vary depending on the type <strong>of</strong> audit<br />

message.<br />

Important: To view audit message files, see “Viewing audit information” on page 18-7.<br />

Sample audit message<br />

The message below is an example <strong>of</strong> a Type Enforcement audit<br />

message (using the te_filter filter). The first three lines <strong>of</strong> this format<br />

applies to all audit message types except netprobes and attack events.<br />

Jan 10 14:56:58 2004 f_kernel a_rover t_ddtviolation<br />

p_major<br />

pid: 5398 ruid: 101 euid: 101 pgid: 5398 fid: 1005379<br />

cmd:‘grep’<br />

domain: User edomain: User<br />

permwanted: 1 permgranted: 0 srcdmn: User filedom: Kern<br />

filetyp: stup<br />

file: ufs_access: rc.local perm wanted: 0x1 perm<br />

granted: 0x0<br />

Monitoring, Auditing, and Reporting 18-19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!