Comment 1 for bug 1831972

Revision history for this message
James Page (james-page) wrote : Re: support fwaas v2 logging

Sample log messages from gateway units:

2019-06-10 09:16:30 action=ACCEPT, project_id=f43842c4647d4912af7817a24c5044b5, log_resource_ids=['2c2353e9-b30b-495a-aa5f-4d720c4e3209'], port=0bf81ded-bf94-437d-ad49-063bba9be9bb, pkt=ethernet(dst='fa:16:3e:1e:ea:0a',ethertype=2048,src='fa:16:3e:41:6f:cc')ipv4(csum=11567,dst='192.168.21.182',flags=2,header_length=5,identification=11808,offset=0,option=None,proto=6,src='10.5.0.10',tos=0,total_length=60,ttl=63,version=4)tcp(ack=0,bits=2,csum=2889,dst_port=22,offset=10,option=[TCPOptionMaximumSegmentSize(kind=2,length=4,max_seg_size=8918), TCPOptionSACKPermitted(kind=4,length=2), TCPOptionTimestamps(kind=8,length=10,ts_ecr=0,ts_val=1575217414), TCPOptionNoOperation(kind=1,length=1), TCPOptionWindowScale(kind=3,length=3,shift_cnt=7)],seq=1144678318,src_port=58300,urgent=0,window_size=26754)

2019-06-10 09:16:34 action=DROP, project_id=f43842c4647d4912af7817a24c5044b5, log_resource_ids=['2c2353e9-b30b-495a-aa5f-4d720c4e3209'], port=0bf81ded-bf94-437d-ad49-063bba9be9bb, pkt=ethernet(dst='fa:16:3e:c6:58:5e',ethertype=2048,src='fa:16:3e:e0:2c:be')ipv4(csum=58033,dst='10.5.0.10',flags=2,header_length=5,identification=30869,offset=0,option=None,proto=6,src='192.168.21.182',tos=16,total_length=52,ttl=63,version=4)tcp(ack=4249435409,bits=17,csum=54161,dst_port=57906,offset=8,option=[TCPOptionNoOperation(kind=1,length=1), TCPOptionNoOperation(kind=1,length=1), TCPOptionTimestamps(kind=8,length=10,ts_ecr=1574867119,ts_val=512608)],seq=3550217559,src_port=22,urgent=0,window_size=3120)

2019-06-10 09:17:26 action=ACCEPT, project_id=f43842c4647d4912af7817a24c5044b5, log_resource_ids=['2c2353e9-b30b-495a-aa5f-4d720c4e3209'], port=0bf81ded-bf94-437d-ad49-063bba9be9bb, pkt=ethernet(dst='fa:16:3e:1e:ea:0a',ethertype=2048,src='fa:16:3e:41:6f:cc')ipv4(csum=59542,dst='192.168.21.182',flags=2,header_length=5,identification=29349,offset=0,option=None,proto=1,src='10.5.0.10',tos=0,total_length=84,ttl=63,version=4)icmp(code=0,csum=30536,data=echo(data=b'% \xfe\\\x00\x00\x00\x00%\xa4\x04\x00\x00\x00\x00\x00\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !"#$%&\'()*+,-./01234567',id=29890,seq=1),type=8)