View Log
Rate Limit
RL RULE=<ridx> DROP=<pkt_number>
This log is triggered every time-period if a rule <ridx> of Connection Limit > Rate Limit is matched. This log indic-
ates connections defined in the Rate Limit rule <ridx> are generated in a rate higher than the limitation, and there
are <pkt_number> packets are dropped for the reason.
See "Connection Limit" for further information.
Cache Redirect
CR {IP‐5‐TUPLE} NEW_DST={ADDR‐PORT}
The first packet of session {IP‐5‐TUPLE} matching a Cache Redirect rule triggers the log. System generates only
one log for this session. This log indicates destination addresses and ports of the packets of {IP‐5‐TUPLE} are
translated to {ADDR} by Virtual Server. The first packet size of the session is <pktlen>.
See "Cache Redirect" for further information.
Multihoming
MH FROM=<ip> TYPE=<A|AAAA> WLINK=<widx> REPLY=<ip>
An DNS response (queried for A or AAAA records) by Multihoming triggers the log. System generates the log only for
DNS queries for A and AAAA records. This log indicates a DNS query whose type is TYPE=<A|AAAA> and comes
from FROM=<ip> is responded by Multihoming with REPLY=<ip>, which is the IP address of WAN link <widx>.
System generates two logs for A and AAAA records if the DNS query type is ANY.
See "Multihoming" for further information.
Dynamic IP
DHCP
DHCP WLINK=<widx> ACTION=<init|renew|rebind|expired|failed|release|stop|bind>
[IP=<ip>]
System triggers the log when a DHCP WAN link <widx> is acted for ACTION. ACTION=bind and IP=<ip> must
be generated in pairs for a log.
PPPoE
PPPOE WLINK=<widx> ACTION=<start|terminated|bind> [IP=<ip>]
FortiWAN Handbook
Fortinet Technologies Inc.
259