05.08.2013 Views

Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...

Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...

Intrusion Defense Firewall 1.2 User's Guide - Trend Micro? Online ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Information IP Don't Fragment bit was set.<br />

The "MF" field is present if the<br />

IP More Fragments bit was set.<br />

The "FRAG=nnn" field contains<br />

the fragment offset value.<br />

Protocol The "PROTO=" field contains<br />

the name of the protocol, or its<br />

numeric format (in decimal) if<br />

it's not one of the well known<br />

values.<br />

Ports The "SPT=" and "DPT=" fields<br />

contains source and destination<br />

ports, if applicable to the<br />

protocol type.<br />

TCP Flags For the TCP protocol, the URG,<br />

ACK, PSH, RST, SYN, FIN fields<br />

are present if the<br />

corresponding TCP header bit<br />

was set. The "RES=0xNN" field<br />

is always present and contains<br />

the value of the reserved TCP<br />

bits. The ECN flags "CWR" and<br />

"ECE" will show up in the two<br />

least significant bits of this<br />

field.<br />

ICMP Flags For the ICMP protocol, the<br />

"TYPE=N" field contains the<br />

ICMP type (in decimal) and the<br />

"CODE=N" field contains the<br />

ICMP code (in decimal).<br />

IP Datagram<br />

Length<br />

The "IPDGLEN=N" field<br />

contains the length of the IP<br />

datagram in decimal format.<br />

DPI Event Log Format<br />

MF FRAG=22<br />

PROTO=TCP<br />

PROTO=UDP<br />

PROTO=ICMP<br />

SPT=137 DPT=137<br />

SPT=41794 DPT=3328<br />

RES=0x00 ACK<br />

RES=0x00 SYN ACK<br />

TYPE=11 CODE=0<br />

TYPE=8 CODE=0<br />

IPDGLEN=0<br />

IPDGLEN=60<br />

As with the <strong>Firewall</strong> Rule syslog format, the Client Plug-in follows the format used by netfilter/iptables<br />

as closely as possible, and adds several <strong>Trend</strong> <strong>Micro</strong> specific fields.<br />

Fields are delimited by a single space character, and consist of a TOKEN or a TOKEN=value string. The<br />

value string will never contain space characters. In the case of items such as rule names or network<br />

interface names, space characters are converted to underscores.<br />

Name Description Examples<br />

Reason The "REASON=" field contains<br />

either a built-in string or the string<br />

"PLD:" followed by the name of the<br />

DPI Rule that caused the log.<br />

Space characters in the DPI Rule<br />

name are converted to<br />

underscores.<br />

Direction The direction of the data flow. FWD<br />

REV<br />

REASON=PLD:Log_HTTP_GET_commands<br />

REASON=URI_Path_Length_Too_Long<br />

© Copyright 2010 <strong>Trend</strong> <strong>Micro</strong> Inc. www.trendmicro.com<br />

All rights reserved. - 90 -

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!