View Tunnel Information in Logs
You can view Tunnel Inspection logs themselves or view tunnel inspection information in other types of logs.
- View Tunnel inspection logs.
- Select MonitorLogsTunnel Inspection and view the log data, noting the tunnel Applications used in your traffic and any high counts for packets failing Strict Checking of headers, for example.
- Click the Detailed Log View icon to see details about a log.
- View other logs for tunnel inspection information.
- Select MonitorLogs.
- Select Traffic, Threat, URL Filtering, WildFire Submissions, Data Filtering, or Unified.
- For a log entry, click the Detailed Log View icon .
- In the Flags window, see if the Tunnel
Inspected flag is checked. A Tunnel Inspected flag indicates
the firewall used a Tunnel Inspection policy rule to inspect the
inside content or inner tunnel. Parent Session information refers
to an outer tunnel (relative to an inner tunnel) or an inner tunnel
(relative to inside content).On the Traffic, Threat, URL Filtering, WildFire Submissions, Data Filtering logs, only direct parent information appears in the Detailed Log View of the inner session log, no tunnel log information. If you configured two levels of tunnel inspection, you can select the parent session of this direct parent to view the second parent log. (You must monitor the Tunnel Inspection log as shown in the prior step to view tunnel log information.)
- If you are viewing the log for an inside session that is tunnel inspected, click the View Parent Session link in the General section to see the outside session information.
Tunnel Content Inspection Logging
For tunnel content inspection, override log settings for Security policy rules to log cleartext tunnel sessions at session start, session end, or both. ...
Tunnel Inspection Logs
Tunnel Inspection Logs Tunnel inspection logs are like traffic logs for tunnel sessions; they display entries of non-encrypted tunnel sessions. To prevent double counting, the ...
Tunnel Content Inspection Overview
Tunnel Content Inspection Overview Your firewall can inspect tunnel content anywhere on the network where you do not have the opportunity to terminate the tunnel ...
Tunnel Inspection Log Fields
Tunnel Inspection Log Fields Format : FUTURE_USE, Receive Time, Serial Number, Type, Subtype, FUTURE_USE, Generated Time, Source IP, Destination IP, NAT Source IP, NAT Destination ...
Tunnel Content Inspection
Tunnel Content Inspection The firewall can inspect the traffic content of cleartext tunnel protocols: Generic Routing Encapsulation (GRE) ( RFC 2784 ) Non-encrypted IPSec traffic ...
Configure Tunnel Content Inspection
Configure Tunnel Content Inspection Perform this task to configure tunnel content inspection for a tunnel protocol that you allow through a tunnel. Create a Security ...
Building Blocks in a Tunnel Inspection Policy
Building Blocks in a Tunnel Inspection Policy Select Policies Tunnel Inspection to add a Tunnel Inspection policy rule. You can use the firewall to inspect ...
Traffic Log Fields
Traffic Log Fields Format: FUTURE_USE, Receive Time, Serial Number, Type, Threat/Content Type, FUTURE_USE, Generated Time, Source IP, Destination IP, NAT Source IP, NAT Destination IP, ...
Threat Log Fields
Threat Log Fields Format : FUTURE_USE, Receive Time, Serial Number, Type, Threat/Content Type, FUTURE_USE, Generated Time, Source IP, Destination IP, NAT Source IP, NAT Destination ...