20.02.2014 Views

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Traffic Logs<br />

SMTP Proxy Traffic Log Messages<br />

Text in Message Field<br />

Associated Fields<br />

SMTP AV ERROR<br />

filename<br />

error<br />

sender<br />

recipient<br />

SMTP REQ<br />

rcvd_bytes<br />

sent_bytes<br />

sender<br />

recipient<br />

SMTP MESSAGE FORMAT<br />

header<br />

mime_error<br />

sender<br />

recipients<br />

SMTP IPS MATCH<br />

ips_msg<br />

signature_id<br />

SMTP TOO MANY RECIPIENTS<br />

num_recipients<br />

SMTP RESPONSE SIZE TOO LONG<br />

headers_size<br />

SMTP LINE LENGTH TOO LONG<br />

line_length<br />

SMTP MESSAGE SIZE TOO LONG<br />

size<br />

SMTP HEADERS SIZE TOO LONG<br />

headers_size<br />

Message Meaning<br />

Value that appears in associated field(s)<br />

The SMTP cannot finish an antivirus scan, usually because an<br />

attachment was encrypted<br />

file name<br />

description of error<br />

sender e-mail address (from envelope)<br />

recipient e-mail addresses (from envelope)<br />

Auditing information about an SMTP request<br />

size of message before proxying<br />

size of message after proxying<br />

sender e-mail address (from envelope)<br />

recipient e-mail addresses (from envelope)<br />

The SMTP header uses a format that is not correct<br />

header with improper format<br />

description of format error<br />

sender e-mail address (from envelope)<br />

recipient e-mail addresses (from envelope)<br />

The SMTP proxy found an IPS signature match<br />

description of the signature that matched<br />

the signature ID of the rule that matched<br />

The number of e-mail addresses in the TO field is larger than the<br />

configured limit<br />

number of recipients<br />

The SMTP server sent a response that is too long<br />

total size of message headers (up to when log emitted; full headers can<br />

be larger)<br />

The SMTP client or server has sent a line that is longer than the<br />

configured limit<br />

total size of header line (up to when log emitted; full line can be larger)<br />

The SMTP client sent a message larger than the configured limit<br />

size in bytes of message received (up to when log emitted; full message<br />

can be larger)<br />

The SMTP client sent a header section that is larger than the SMTP limit<br />

total size of message headers (up to when log emitted; full headers can<br />

be larger)<br />

DNS Proxy Traffic Log Messages<br />

Text in Message Field<br />

Associated Fields<br />

DNS INVALID NUMBER OF QUESTIONS<br />

DNS OVERSIZED QUERY NAME<br />

DNS COMPRESSED QUERY NAME<br />

DNS PARSE ERROR<br />

DNS NOT INTERNET CLASS<br />

query_class<br />

DNS DENIED OPCODE<br />

rulename<br />

query_opcode<br />

DNS DENIED QUERY TYPE<br />

rulename<br />

query_type<br />

DNS UNDERSIZED QUESTION<br />

Message Meaning<br />

Value that appears in associated field(s)<br />

There is more than one RRs inquiry in one DNS request<br />

The total DNS query frame size is larger than the DNS protocol limit<br />

The client used a DNS compression scheme in the query name<br />

The DNS request or respone is not in the correct format.<br />

The DNS query is not in IP protocol format<br />

name or number of its class<br />

The opcode matches a configured proxy rule<br />

name of rule matched in ruleset<br />

name of the denied opcode (IQUERY, STATUS, UPDATE)<br />

The query type matches a configured proxy rule<br />

name of rule matched in ruleset<br />

name of denied type (a, MX, NS)<br />

The name component of the DNS query is too small<br />

32 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!