Mettle Knowledge
Search:     Advanced search
Browse by category:
Contact Us

Firewall Logs

Add comment
Views: 429
Votes: 0
Comments: 0
Posted: 31 May, 2010
by: Knowledge M.
Updated: 31 May, 2010
by: Knowledge M.

A firewall log entry is made for each rule that is set to log and for the default deny rule.

To view the parsed logs you have to go to Status -> System Logs on the Firewall tab.

Parsed logs are displayed in 6 columns: Action - Time - Interface - Source - Destination - Protocol. Action tells what happened to the packet which generated the log entry - its either Pass, Block, or Reject. Time tells the time when the packet has arrived. Interface is the interface through which the packet entered Mettle SE. Source is the source IP address and the port the packet originated from, Destination is the destination IP address and port of the packet. Protocol is the protocol of the packet.

The 'Action' icon displayed in the logs is a link, clicking it will lookup and display the rule which caused the log entry.

If the Protocol is TCP, you will see extra fields that represent TCP flags present in the packet. These flags indicate various connection states or packet attributes, some common flags are:

  • S (Syn) - Synchronise sequence numbers. Indicates a new connection attempt when only SYN is set.
  • A (Ack) - Acknowledgemet to the data received.
  • F (Fin) - Indicates there is no more data from the sender, connection closing.
  • R (Rst) - Connection reset
There are several other flags and their meaning is outlined in articles realted to TCP protocols
http://en.wikipedia.org/wiki/Transmission_Control_Protocol
Also read
document Adding Firewall Rules

Others in this Category
document Initial Configuration: Setting up Mettle SE in a Local Area Network with Internet Connection.
document Default IP Address & Admin Password (And How To Change It?)
document Configuring DHCP Server
document Enabling The LAN Hosts To Use The Internet Connection (NATing)
document Adding A Second (Or More) Internet Connection To Mettle SE & Setting Up Failover/Load Balancing
document Monitoring The Internet Usage
document How To Turn On/Off The Content Filter & Gateway Antivirus Service
document Fine Tuning The Content Scanner
document Setting Up PPTP VPN accounts
document OpenVPN: Setting Up SSL-VPN accounts
document Setting Up IPsec VPN Accounts
document Deploying A Second LAN With Mettle SE.
document Choosing a VPN Technology
document Adding Firewall Rules
document Setting Up Mettle SE Stack for Active/Passive Fail-Over (CARP)
document Connecting & Securing a Leased Line Connection to Mettle SE
document Port Forwarding (PAT)
document Creating a DNS Entry/Record for the LAN
document Blocking GTalk in the LAN
document Blocking Yahoo! IM from the LAN
document OpenVPN: If VPN Clients Want to Access a Subnet other than "Local network"
document Setting up IPSec Tunnel
document Open VPN Troubleshooting
document PPTP VPN Troubleshooting
document NTP Client/Server
document Setting Up an IPSec VPN Client: Example Given Using Shrewsoft VPN Client
document Firewall: Alias
document Captive Portal
document Virtual IP Address
document OpenVPN: Setting Up a SSL-VPN Client in Windows
document Creating Tagged VLANs
document Cloning Firewall Rules
document IPsec VPN Troubleshooting
document Wake On LAN
document Inbound Loadbalancing
document OpenVPN: Setting up Certification Authority & Generating Certificates
document Changing default webGUI Port and Protocol
document Using Packet Capture
document Using Traceroute
document Package Updates
document OpenVPN: To make OpenVPN client use VPN as the Default Gateway
document OpenVPN: To exclude some Network from using VPN gateway when VPN is set as default gateway for VPN client
document Adding a Static DHCP Lease
document Schedule Based Firewall Rules
document RRD Graphs
document Server Load Balancing
document Backup and Restore Mettle SE Running Configuration
document Event Logging To Remote Syslog Server
document Split DNS
document NAT Reflection/NAT Loopback
document Dynamic DNS



RSS