Page 211 / 324 Scroll up to view Page 206 - 210
P-660HN-TxA User’s Guide
211
C
HAPTER
20
Logs
20.1
Overview
This chapter contains information about viewing the ZyXEL Device’s logs.
The web configurator allows you to choose which types of events and/or alerts to
have the ZyXEL Device log and then display the logs.
20.1.1
What You Need To Know About Logs
Alerts
An alert is a message that is enabled as soon as the event occurs. They include
system errors, attacks (access control) and attempted access to blocked web
sites. Some categories such as
System Errors
consist of both logs and alerts. You
may differentiate them by their color in the
View Log
screen. Alerts display in red
and logs display in black.
Logs
A log is a message about an event that occurred on your ZyXEL Device. For
example, when someone logs in to the ZyXEL Device, you can set a schedule for
how often logs should be enabled, or sent to a syslog server.
20.2
The System Log Screen
Use the
System
Log
screen to configure and view the logs you wish to display.
To change your ZyXEL Device’s log settings, click
Maintenance > Logs
>
Log
Settings
. The screen appears as shown.
Page 212 / 324
Chapter 20 Logs
P-660HN-TxA User’s Guide
212
Alerts are e-mailed as soon as they happen. Logs may be e-mailed as soon as the
log is full. Selecting many alert and/or log categories (especially
Access Control
)
may result in many e-mails being sent.
Figure 101
Maintenance > System Logs
The following table describes the fields in this screen.
Table 73
Maintenance > Logs > Log Settings
LABEL
DESCRIPTION
System Log
Log Type
Select the types of logs that you want to display and record. Then click
Submit
to display the details.
Clear Log
Click this to delete all the logs.
Save Log
Click this to save the logs in a text file.
Page 213 / 324
Chapter 20 Logs
P-660HN-TxA User’s Guide
213
20.3
Log Descriptions
This section provides descriptions of example log messages.
Table 74
System Maintenance Logs
LOG MESSAGE
DESCRIPTION
Time calibration is
successful
The router has adjusted its time based on information
from the time server.
Time calibration failed
The router failed to get information from the time
server.
WAN interface gets IP: %s
A WAN interface got a new IP address from the DHCP,
PPPoE, or dial-up server.
DHCP client IP expired
A DHCP client's IP address has expired.
DHCP server assigns %s
The DHCP server assigned an IP address to a client.
Successful WEB login
Someone has logged on to the router's web
configurator interface.
WEB login failed
Someone has failed to log on to the router's web
configurator interface.
Successful TELNET login
Someone has logged on to the router via telnet.
TELNET login failed
Someone has failed to log on to the router via telnet.
Successful FTP login
Someone has logged on to the router via ftp.
FTP login failed
Someone has failed to log on to the router via ftp.
NAT Session Table is Full!
The maximum number of NAT session table entries
has been exceeded and the table is full.
Starting Connectivity
Monitor
Starting Connectivity Monitor.
Time initialized by Daytime
Server
The router got the time and date from the Daytime
server.
Time initialized by Time
server
The router got the time and date from the time
server.
Time initialized by NTP
server
The router got the time and date from the NTP server.
Connect to Daytime server
fail
The router was not able to connect to the Daytime
server.
Connect to Time server fail
The router was not able to connect to the Time server.
Connect to NTP server fail
The router was not able to connect to the NTP server.
Too large ICMP packet has
been dropped
The router dropped an ICMP packet that was too
large.
Configuration Change: PC =
0x%x, Task ID = 0x%x
The router is saving configuration changes.
Successful SSH login
Someone has logged on to the router’s SSH server.
SSH login failed
Someone has failed to log on to the router’s SSH
server.
Page 214 / 324
Chapter 20 Logs
P-660HN-TxA User’s Guide
214
Successful HTTPS login
Someone has logged on to the router's web
configurator interface using HTTPS protocol.
HTTPS login failed
Someone has failed to log on to the router's web
configurator interface using HTTPS protocol.
Table 75
System Error Logs
LOG MESSAGE
DESCRIPTION
%s exceeds the max.
number of session per
host!
This attempt to create a NAT session exceeds the
maximum number of NAT session table entries allowed to
be created per host.
setNetBIOSFilter: calloc
error
The router failed to allocate memory for the NetBIOS
filter settings.
readNetBIOSFilter: calloc
error
The router failed to allocate memory for the NetBIOS
filter settings.
WAN connection is down.
A WAN connection is down. You cannot access the
network through this interface.
Table 76
Access Control Logs
LOG MESSAGE
DESCRIPTION
Firewall default policy: [ TCP |
UDP | IGMP | ESP | GRE | OSPF ]
<Packet Direction>
Attempted TCP/UDP/IGMP/ESP/GRE/OSPF access
matched the default policy and was blocked or
forwarded according to the default policy’s
setting.
Firewall rule [NOT] match:[ TCP
| UDP | IGMP | ESP | GRE | OSPF
] <Packet Direction>, <rule:%d>
Attempted TCP/UDP/IGMP/ESP/GRE/OSPF access
matched (or did not match) a configured firewall
rule (denoted by its number) and was blocked or
forwarded according to the rule.
Triangle route packet forwarded:
[ TCP | UDP | IGMP | ESP | GRE |
OSPF ]
The firewall allowed a triangle route session to
pass through.
Packet without a NAT table entry
blocked: [ TCP | UDP | IGMP |
ESP | GRE | OSPF ]
The router blocked a packet that didn't have a
corresponding NAT table entry.
Router sent blocked web site
message: TCP
The router sent a message to notify a user that
the router blocked access to a web site that the
user requested.
Table 74
System Maintenance Logs (continued)
LOG MESSAGE
DESCRIPTION
Page 215 / 324
Chapter 20 Logs
P-660HN-TxA User’s Guide
215
Table 77
TCP Reset Logs
LOG MESSAGE
DESCRIPTION
Under SYN flood attack,
sent TCP RST
The router sent a TCP reset packet when a host was
under a SYN flood attack (the TCP incomplete count is per
destination host.)
Exceed TCP MAX
incomplete, sent TCP RST
The router sent a TCP reset packet when the number of
TCP incomplete connections exceeded the user configured
threshold. (the TCP incomplete count is per destination
host.) Note: Refer to
TCP Maximum Incomplete
in the
Firewall Attack Alerts
screen.
Peer TCP state out of
order, sent TCP RST
The router sent a TCP reset packet when a TCP
connection state was out of order.Note: The firewall refers
to RFC793 Figure 6 to check the TCP state.
Firewall session time
out, sent TCP RST
The router sent a TCP reset packet when a dynamic
firewall session timed out.Default timeout values:ICMP
idle timeout (s): 60UDP idle timeout (s): 60TCP
connection (three way handshaking) timeout (s): 30TCP
FIN-wait timeout (s): 60TCP idle (established) timeout
(s): 3600
Exceed MAX incomplete,
sent TCP RST
The router sent a TCP reset packet when the number of
incomplete connections (TCP and UDP) exceeded the
user-configured threshold. (Incomplete count is for all
TCP and UDP connections through the firewall.)Note:
When the number of incomplete connections (TCP + UDP)
> “Maximum Incomplete High”, the router sends TCP RST
packets for TCP connections and destroys TOS (firewall
dynamic sessions) until incomplete connections <
“Maximum Incomplete Low”.
Access block, sent TCP
RST
The router sends a TCP RST packet and generates this log
if you turn on the firewall TCP reset mechanism (via CI
command: "sys firewall tcprst").
Table 78
Packet Filter Logs
LOG MESSAGE
DESCRIPTION
[ TCP | UDP | ICMP | IGMP |
Generic ] packet filter
matched (set: %d, rule: %d)
Attempted access matched a configured filter rule
(denoted by its set and rule number) and was blocked
or forwarded according to the rule.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top