Skip to main content
Skip table of contents

V 2.0 SCTP Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 SCTP Messages

Base Rule

General Network Traffic

Network Traffic

V 2.0 Traffic Allowed By Network Firewall Messages

Sub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0 Traffic Denied By Network FirewallSub RuleTraffic Denied by Network FirewallNetwork Deny

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Type (type)<vmid>Text/StringSpecifies the type of log; value is SCTP.
Source Address (src)<sip>IP AddressOriginal session source IP address
Destination Address (dst)<dip>IP AddressOriginal session destination IP address
Rule Name (rule)<policy>Text/StringName of the Security policy rule in effect on the session.
Inbound Interface (inbound_if)<sinterface>Text/StringInterface that the session was sourced from
Outbound Interface (outbound_if)<dinterface>Text/StringInterface that the session was destined to
Session ID (sessionid)<session>NumberAn internal numerical identifier applied to each session
Source Port (sport)<sport>NumberSource port utilized by the session
Destination Port (dport)<dport>NumberDestination port utilized by the session
IP Protocol (proto)<protname>Text/StringIP protocol associated with the session
Action (action)<action>
<tag1>
Text/StringAction taken for the session; possible values are:
allow—session was allowed by the policy
deny—session was denied by the policy
Device Name (device_name)<objectname>Text/StringThe hostname of the firewall on which the session was logged
Severity (severity)<severity>Text/StringSeverity associated with the event; values are informational, low, medium, high, critical.
SCTP Event Type (sctp_event_type)<subject>Text/StringDefines the event triggered per SCTP chunk or packet when SCTP protection profile is applied to the SCTP traffic. It is also triggered by start or end of a SCTP association.
SCTP Association End Reason (assoc_end_reason)<reason>Text/StringReason an association was terminated. If the termination had multiple causes, the highest priority reason is displayed. The possible session end reasons in descending priority are:
shutdown-from-endpoint (highest)—endpoint sends out SHUTDOWN
abort-from-endpoint—endpoint sends out ABORT
unknown (lowest)—the association aged out, or association termination reason is not covered by one of the previous reasons (for example, a clear session all command).
Packets Sent (pkts_sent)<packetsout>NumberNumber of client-to-server packets for the session
Packets Received (pkts_received)<packetsin>NumberNumber of server-to-client packets for the session
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.