12.07.2015 Views

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Alarm LogsDenial of Servce (DoS) AlarmsDefaultNamePort-ScanMessage Format Example Message Caused Byalarm_name detected.message_string.Port-Scan detected. Port scanthreshold 300 reached, 300 portsscanned by 192.168.228.226 in 10seconds.These alarms aretriggered by Port SpaceProbe attacks.IP-Scanalarm_name detected.message_string.IP-Scan detected. IP scan threshold300 reached, 300 IPs scanned by192.168.228.226 in 10 seconds.These alarms aretriggered by AddressSpace Probe attacks.IP-Spoofingalarm_name detected.message_string.IP-Spoofing detected. IP sourcespoofing detected, src_intf=30,src_ip=192.168.228.226.These alarms aretriggered by IP Spoofingattacks.Tear-Dropalarm_name detected. TEAR-DROPattack detected on interfaceinterface_number.Tear-Drop detected. TEAR-DROPattack detected on interface 1.These alarms aretriggered by Tear-Dropattacks.Traffic AlarmsDefaultNameTrafficESP-Auth-ErrorAH-Auth-ErrorMessage Format Example Message Caused Byalarm _name detected,message_string.alarm_name detected. ESPAuthentication error,policy_id=policy_id_number,local_ip=local_IP_address,peer_ip=peer_IP_address, spi=spi,sa_id=ID_of_SA,interface=interface_number, thefirst (x) bytes are list_of_first xnumber of bytes.alarm_name detected. AHAuthentication error,policy_id=policy_id_number,local_ip=local_IP_address,peer_ip=peer_IP_address, spi=spi,sa_id=ID_of_SA,interface=interface_number, thefirst (x) bytes are list_of_first xnumber of bytes.NOTE: The content of this alarmmessage is based on what trafficevent triggered the alarm. See theexamples below.ESP-Auth-Error detected. ESPAuthentication error, policy_id=2,local_ip=10.10.10.10,peer_ip=192.168.228.226,spi=12345678, sa_id=1000,interface=1, the first 80 bytes areA0 B1 C2.........AH-Auth-Error detected. AHAuthentication error, policy_id=2,local_ip=10.10.10.10,peer_ip=192.168.228.226,spi=12345678, sa_id=1000,interface=1, the first 80 bytes areA0 B1 C2.........These alarms aretriggered by any trafficevents.These alarms aretriggered by the trafficevent “ESP-AUTH_ERR”.These alarms aretriggered by the trafficevent “AH_AUTH_ERR”.<strong>Reference</strong> <strong>Guide</strong> 39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!