30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

22.5 Connection Log<br />

A typical example of this record type is the change of traffic rules. When the user hits<br />

Apply in Configuration → Traffic policy, a complete list of current traffic rules is written<br />

to the Config log.<br />

Example:<br />

[18/Apr/2008 12:06:03] Admin - New traffic policy set:<br />

[18/Apr/2008 12:06:03] Admin - 1: name=(ICMP traffic)<br />

src=(any) dst=(any) service=("Ping")<br />

snat=(any) dnat=(any) action=(Permit)<br />

time_range=(always) inspector=(default)<br />

• [18/Apr/2003 12:06:03] — date and time of the change<br />

• Admin — login name of the user who did the change<br />

• 1: — traffic rule number (rules are numbered top to bottom according to<br />

their position in the table, the numbering starts from 1)<br />

• name=(ICMP Traffic) ... — traffic rule definition (name, source,<br />

destination, service etc.)<br />

Note: The default rule (see chapter 7.1) is marked with default instead of the positional<br />

number.<br />

22.5 Connection Log<br />

The Connection log gathers information about traffic matching traffic rules with the Log matching<br />

connections enabled (see chapter 7) or meeting certain conditions (e.g. log of UPnP traffic<br />

— see chapter 18.2).<br />

How to read the Connection Log<br />

[18/Apr/2008 10:22:47] [ID] 613181 [Rule] NAT<br />

[Service] HTTP [User] james<br />

[Connection] TCP 192.168.1.140:1193 -> hit.google.com:80<br />

[Duration] 121 sec [Bytes] 1575/1290/2865 [Packets] 5/9/14<br />

• [18/Apr/2008 10:22:47] — date and time when the event was logged (note:<br />

Connection logs are saved immediately after a disconnection).<br />

• [ID] 613181 — <strong>Kerio</strong> Control connection identification number<br />

• [Rule] NAT — name of the traffic rule which has been used (a rule by which the traffic<br />

was allowed or denied).<br />

• [Service] HTTP — name of a corresponding application layer service (recognized by<br />

destination port).<br />

291

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!