簡介
本文檔說明雲交付的防火牆日誌中缺少埠資訊的原因。
為什麼我的雲交付防火牆日誌中缺少埠資訊?
當您從思科的託管S3儲存桶或您自己的S3儲存桶下載Cisco Umbrella日誌時,某些雲交付防火牆(CDFW)日誌會為「sourcePort」和「destinationPort」輸入返回空值。
使用者流量的內部連線埠資訊是否可用取決於流量的通訊協定。由於ICMP流量沒有埠號,因此不會記錄埠資訊。
"2020-06-09 18:52:38","[419244240]","raspberrypi","Network Tunnels",
"OUTBOUND","1","84","192.168.64.112","","8.8.8.8","","nyc1.edc",
"1614180","ALLOW"
當記錄使用TCP和UDP的流量時,將顯示埠資訊。
"2020-06-09 18:53:49","[419244240]","raspberrypi","Network Tunnels",
"OUTBOUND","17","75","192.168.64.112","57405","8.8.8.8","53","nyc1.edc",
"1614180","ALLOW"
其他資訊
在Umbrella文檔中閱讀有關CDFW日誌的更多內容:日誌格式和版本控制 — 雲防火牆日誌