Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...
Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...
Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Information IP Don't Fragment bit was set.<br />
The "MF" field is present if the<br />
IP More Fragments bit was set.<br />
The "FRAG=nnn" field contains<br />
the fragment offset value.<br />
Protocol The "PROTO=" field contains<br />
the name of the protocol, or its<br />
numeric format (in decimal) if<br />
it's not one of the well known<br />
values.<br />
Ports The "SPT=" and "DPT=" fields<br />
contains source and destination<br />
ports, if applicable to the<br />
protocol type.<br />
TCP Flags For the TCP protocol, the URG,<br />
ACK, PSH, RST, SYN, FIN fields<br />
are present if the<br />
corresponding TCP header bit<br />
was set. The "RES=0xNN" field<br />
is always present and contains<br />
the value of the reserved TCP<br />
bits. The ECN flags "CWR" and<br />
"ECE" will show up in the two<br />
least significant bits of this<br />
field.<br />
ICMP Flags For the ICMP protocol, the<br />
"TYPE=N" field contains the<br />
ICMP type (in decimal) and the<br />
"CODE=N" field contains the<br />
ICMP code (in decimal).<br />
IP Datagram<br />
Length<br />
The "IPDGLEN=N" field<br />
contains the length of the IP<br />
datagram in decimal format.<br />
DPI Event Log Format<br />
MF FRAG=22<br />
PROTO=TCP<br />
PROTO=UDP<br />
PROTO=ICMP<br />
SPT=137 DPT=137<br />
SPT=41794 DPT=3328<br />
RES=0x00 ACK<br />
RES=0x00 SYN ACK<br />
TYPE=11 CODE=0<br />
TYPE=8 CODE=0<br />
IPDGLEN=0<br />
IPDGLEN=60<br />
As with the <strong>Firewall</strong> Rule syslog format, the Client Plug-in follows the format used by netfilter/iptables<br />
as closely as possible, and adds several <strong>Trend</strong> <strong>Micro</strong> specific fields.<br />
Fields are delimited by a single space character, and consist of a TOKEN or a TOKEN=value string. The<br />
value string will never contain space characters. In the case of items such as rule names or network<br />
interface names, space characters are converted to underscores.<br />
Name Description Examples<br />
Reason The "REASON=" field contains<br />
either a built-in string or the string<br />
"PLD:" followed by the name of the<br />
DPI Rule that caused the log.<br />
Space characters in the DPI Rule<br />
name are converted to<br />
underscores.<br />
Direction The direction of the data flow. FWD<br />
REV<br />
REASON=PLD:Log_HTTP_GET_commands<br />
REASON=URI_Path_Length_Too_Long<br />
© Copyright 2010 <strong>Trend</strong> <strong>Micro</strong> Inc. www.trendmicro.com<br />
All rights reserved. - 90 -