Message
DLP/4/ABNFILE(l): An abnormal file was transmitted.
(SyslogId=[syslog-id], Policy=[policy-name], SrcIp=[source-ip], DstIp=[destination-ip], SrcPort=[source-port], DstPort=[destination-port], SrcZone=[source-zone], DstZone=[destination-zone], Protocol=[protocol],
Application=[application-name], Direction=[direction], FileName=[file-name], Abnormal=[abnormal], Action=[action])
Description
Anomalies were detected in a file being transmitted.
Parameters
Parameter Name |
Parameter Meaning |
syslog-id |
Log ID |
policy-name |
Name of the security policy |
source-ip |
Source IP address of packets |
destination-ip |
Destination IP address of packets |
source-port |
Source port of packets (the value is 0 for ICMP
packets) |
destination-port |
Destination port of packets (the value is 0 for
ICMP packets) |
source-zone |
Source security zone of packets |
destination-zone |
Destination security zone of packets |
protocol |
Protocol of the packets matching the signature |
application-name |
Protocol that carries the packets |
direction |
File transfer direction |
file-name |
Name of the filtered file |
abnormal |
Types of file anomalies:
- false extension file
- malformed file
- unknown file
- decompress overdepth
- decompress oversize
|
action |
Action for the signature
|
Possible Causes
The type of the file being transmitted did not match
its file name extension.
Procedure
- This log message indicates a normal situation, and no action
is required.