简介
本文档说明云交付的防火墙日志中缺少端口信息的原因。
为什么云交付的防火墙日志中缺少端口信息?
当您从思科托管S3存储桶或您自己的S3存储桶下载Cisco Umbrella日志时,一些云交付防火墙(CDFW)日志会为“sourcePort”和“destinationPort”输入返回空值。
用户流量的内部端口信息是否可用取决于流量的协议。由于ICMP流量没有端口号,因此不会记录端口信息。
"2020-06-09 18:52:38","[419244240]","raspberrypi","Network Tunnels",
"OUTBOUND","1","84","192.168.64.112","","8.8.8.8","","nyc1.edc",
"1614180","ALLOW"
记录使用TCP和UDP的流量时,会显示端口信息。
"2020-06-09 18:53:49","[419244240]","raspberrypi","Network Tunnels",
"OUTBOUND","17","75","192.168.64.112","57405","8.8.8.8","53","nyc1.edc",
"1614180","ALLOW"
Additional Information
阅读Umbrella文档中有关CDFW日志的更多信息:日志格式和版本控制 — 云防火墙日志