HP LaserJet Enterprise, HP PageWide Enterprise - HP Security Event Logging Messaging Reference (white paper)

Chapter 2 Enhanced security event logging 109
AP
STA
Message:
<device type>: IPsec/Firewall rule disabled; time="<timestamp>" rule=<rule number>
user=<user>source_IP="<client computer IP address>" outcome=success interface=<interface>
Interface(s):
EWS
Syslog severity:
Warning
Explanation:
An IPsec/Firewall rule was disabled.
Variables:
<device type> - see Table 2-2.
<timestamp> - see Table 2-2.
<rule index> - Index of rule in the rules list. Possible values are: 1 - 10
<user> - User who disabled the IPsec/Firewall rule.
<client computer IP address> - IP address of the client computer that sent the request to disable
the IPsec/Firewall rule.
<interface> - Networking interface on the device that received the request to disable the
IPsec/Firewall rule. Possible values are:
Wired
AP
STA
Message:
<device type>: IPsec/Firewall default rule action modified; time="<timestamp>" value=<value>
old_value=<old value> user=<user>source_IP="<client computer IP address>"
outcome=success interface=<interface>
Interface(s):
EWS
Syslog severity:
Warning
Explanation:
The action-on-match for the default IPsec/Firewall rule was modified.
Variables:
<device type> - see Table 2-2.
<timestamp> - see Table 2-2.
<value> - New action-on-match. Possible values are:
allow
drop
<old value> - Old action-on-match. Possible values are:
allow
drop
<user> - User who modified the action-on-match for the default IPsec/Firewall rule.
<client computer IP address> - IP address of the client computer that sent the request to modify
the action-on-match for the default IPsec/Firewall rule.
<interface> - Networking interface on the local device that received the request to modify the
action-on-match for the default IPsec/Firewall rule. Possible values are:
Wired
AP
STA