ZyXEL P-202H Plus User Guide - Page 233

P-202H Plus v2 User's Guide, Enabling the Firewall, View Firewall Log

Page 233 highlights

P-202H Plus v2 User's Guide Table 77 View Firewall Log FIELD DESCRIPTION EXAMPLES # This is the index number of the firewall log. 128 entries 23 are available numbered from 0 to 127. Once they are all used, the log wraps around and the old logs are lost. Time This is the time the log was recorded in this format. You mm:dd:yy: e.g., Jan 1 00 must configure menu 24.10 for real time; otherwise the hh:mm:ss: e.g., 00:00:00 clock will start at 2000/01/01 00:00:00 the last time the ZyXEL Device was reset. Packet Information This field lists packet information such as protocol and src/dest port numbers (TCP, UDP), or protocol, type and code (ICMP). From and To IP addresses Protocol and port numbers Reason This field states the reason for the log; i.e., was the rule matched, did not match or was there an attack. The set and rule coordinates ( where X=1,2; Y=00~10) follow with a simple explanation. There are two policy sets; set 1 (X = 1) is for LAN to WAN rules and set 2 (X = 2) for WAN to LAN rules. Y represents the rule in the set. You can configure up to 10 rules in any set (Y = 01 to 10). Rule number 00 is the default rule. not match dest IP This means this packet does not match the destination IP address in set 1, rule 1. Other reasons (instead of dest IP) are src IP, dest port, src port and protocol. This is a log for a DoS attack. attack land, ip spoofing, icmp echo, icmp vulnerability, NetBIOS, smtp illegal command, traceroute, teardrop or syn flood Action This field displays whether the packet was blocked or forwarded. None means that no action is dictated by this rule. block, forward or none After viewing the firewall log, ENTER "y" to clear the log or "n" to retain it. With either option you will be returned to Menu 21- Filter and Firewall Setup. Chapter 24 Enabling the Firewall 232

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375

P-202H Plus v2 User’s Guide
Chapter 24 Enabling the Firewall
232
Table 77
View Firewall Log
FIELD
DESCRIPTION
EXAMPLES
#
This is the index number of the firewall log. 128 entries
are available numbered from 0 to 127. Once they are
all used, the log wraps around and the old logs are lost.
23
Time
This is the time the log was recorded in this format. You
must configure menu 24.10 for real time; otherwise the
clock will start at 2000/01/01 00:00:00 the last time the
ZyXEL Device was reset.
mm:dd:yy: e.g., Jan 1 00
hh:mm:ss: e.g., 00:00:00
Packet Information
This field lists packet information such as protocol and
src/dest port numbers (TCP, UDP), or protocol, type
and code (ICMP).
From and To IP
addresses
Protocol and port
numbers
Reason
This field states the reason for the log; i.e., was the rule
matched, did not match or was there an attack. The set
and rule coordinates (<X, Y> where X=1,2; Y=00~10)
follow with a simple explanation. There are two policy
sets; set 1 (X = 1) is for LAN to WAN rules and set 2 (X
= 2) for WAN to LAN rules. Y represents the rule in the
set. You can configure up to 10 rules in any set (Y = 01
to 10). Rule number 00 is the default rule.
not match
<1,01> dest IP
This means this packet
does not match the
destination IP address in
set 1, rule 1. Other
reasons (instead of dest
IP) are src IP, dest port,
src port and protocol.
This is a log for a DoS attack.
attack
land, ip spoofing, icmp
echo, icmp vulnerability,
NetBIOS, smtp illegal
command, traceroute,
teardrop or syn flood
Action
This field displays whether the packet was blocked or
forwarded. None means that no action is dictated by
this rule.
block, forward or none
After viewing the firewall log, ENTER “y” to clear the log or “n” to retain it.
With either option you will be
returned to
Menu 21- Filter and Firewall Setup
.