EasyManuals Logo

Allied Telesis AR Series User Manual

Allied Telesis AR Series
75 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #69 background imageLoading...
Page #69 background image
C613-22104-00 REV B URL Filtering Log Messages | Page 69
Logging Advanced Network Protection
URL Filtering Log Messages
By default, URL filtering messages are generated when there are:
Blacklist and whitelist hits—logged at severity info (6) level.
Invalid match criteria, detected while loading third party and custom blacklist and whitelist files—
logged at err (3) level.
Missing configured custom blacklist and/or whitelist files, while starting/restarting the feature—
logged at warning (4) level.
From AlliedWare Plus version 5.4.7-1.x, you can turn on additional URL request logging to log all
URL requests, including permitted requests. Use the following commands:
awplus(config)# url-filter
awplus(config-url-filter)# log url-requests
Log messages for blacklist or whitelist hits include information in the following format:
<action> URLFILTER: [URL:<url>] <protocol> <source-ip>:<source-port> ->
<dest-ip>:<dest-port>
Output 9: Example Malware Protection log messages
2016 Nov 17 02:13:08 local5.info awplus IPS[1939]: [Drop] MALWARE: Virus
detected by signature URL:http:/[172.16.92.2]/data/byte/sample.exe [http]
172.16.92.2:80 -> 192.168.92.1:60784
2016 Nov 17 02:32:02 local5.info awplus IPS[2014]: [Drop] MALWARE: Virus
detected by signature [tcp] 172.16.92.2:42168 -> 192.168.92.1:45528
2016 Nov 17 02:33:59 local5.info awplus IPS[1913]: [Drop] MALWARE: File with
known bad MD5 detected (ITW) URL:http:/[172.16.92.2]/data/md5/EICAR-Test-File
[http] 172.16.92.2:80 -> 192.168.92.1:60820
2016 Nov 17 02:36:32 local5.info awplus IPS[2004]: [Drop] MALWARE: File with
known bad MD5 detected (ITW) [smtp] 192.168.92.1:45820 -> 172.16.92.2:25
Table 8: URL Filtering log message elements
Message element Description
<action>
Which action is applied; [ALERT], [DROP] or [http].
<url>
The requested URL if the flow is HTTP.
<protocol>
The protocol e.g., SMTP, HTTP, TCP, ICMP.
<source-ip>:<source-port>
The source IP address and source port for the packet.
<dest-ip>:<dest-port>
The destination IP address and source port for the packet.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Allied Telesis AR Series and is the answer not in the manual?

Allied Telesis AR Series Specifications

General IconGeneral
BrandAllied Telesis
ModelAR Series
CategoryFirewall
LanguageEnglish

Related product manuals