ZyXEL Vantage Report 2.3 User Guide - Page 667
Syslog Logs
View all ZyXEL Vantage Report 2.3 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 667 highlights
Appendix C ZyNOS Log Descriptions Table 317 AS Directions for Single WAN Devices FROM\TO LAN WAN DMZ LAN (L to L) (L to W) (L to D) WAN (W to L) (W to W) (W to D) DMZ (D to L) (D to W) (D to D) WLAN (WL to L) (WL to W) (WL to D) WLAN (L to WL) (W to WL) (D to WL) (WL to WL) Syslog Logs There are two types of syslog: event logs and traffic logs. The device generates an event log when a system event occurs, for example, when a user logs in or the device is under attack. The device generates a traffic log when a "session" is terminated. A traffic log summarizes the session's type, when it started and stopped the amount of traffic that was sent and received and so on. An external log analyzer can reconstruct and analyze the traffic flowing through the device after collecting the traffic logs. Table 318 Syslog Logs LOG MESSAGE DESCRIPTION Event Log: Mon dd hr:mm:ss hostname src="" dst="" msg="" note="" devID="" cat="" This message is sent by the system ("RAS" displays as the system name if you haven't configured one) when the router generates a syslog. The facility is defined in the web MAIN MENU, LOGS, Log Settings page. The severity is the log's syslog class. The definition of messages and notes are defined in the other log tables. The "devID" is the MAC address of the router's LAN port. The "cat" is the same as the category in the router's logs. Traffic Log: Mon dd hr:mm:ss hostname src="" dst="" msg="Traffic Log" note="Traffic Log" devID="" cat="Traffic Log" duration=seconds sent=sentBytes rcvd=receiveBytes dir="" protoID=IPProtocolID proto="serviceName" trans="IPSec/Normal" This message is sent by the device when the connection (session) is closed. The facility is defined in the Log Settings screen. The severity is the traffic log type. The message and note always display "Traffic Log". The "proto" field lists the service name. The "dir" field lists the incoming and outgoing interfaces ("LAN:LAN", "LAN:WAN", "LAN:DMZ", "LAN:DEV" for example). Vantage Report User's Guide 667