iyotov
Staff
Created on 04-23-2018 06:32 AM Edited on 11-23-2021 07:25 AM By Anonymous
Article Id
192686
Description
This article explains why the UTM logs for ICMP traffic contain source and destination port numbers.
Solution
For ICMP UTM logs, the "dstport" field is used to display the ICMP code, and "srcport" is showing the sequence number from the ICMP payload.
More information regarding Internet Control Message Protocol and a description of the ICMP parameters can be found at external sites such as:
https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml
and
https://en.wikipedia.org/wiki/Internet_Control_Message_Protocol
More information regarding Internet Control Message Protocol and a description of the ICMP parameters can be found at external sites such as:
https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml
and
https://en.wikipedia.org/wiki/Internet_Control_Message_Protocol