Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

44033 - LOGID_EVENT_VOIP_SIP_BLOCK

44033 - LOGID_EVENT_VOIP_SIP_BLOCK

Message ID: 44033

Message Description: LOGID_EVENT_VOIP_SIP_BLOCK

Message Meaning: VoIP SIP blocked

Type: VoIP

Category: VOIP

Severity: Notice

Log Field Name

Description

Data Type

Length

action

Action. Eg. block , allow

string

15

call_id

Ex: call_id="1-22011@10.6.30.11"

string

64

count

Session count

uint32

10

date

Day, month, and year when the log message was recorded.

string

10

devid

Serial number of the device for the traffic's origin.

string

16

dir

Destination Interface

string

16

dstip

Destination IP

ip

39

dst_int

Destination Interface

string

16

dst_port

Destination port

uint16

5

duration

Duration of the session. Ex: 180 (in seconds)

uint32

10

epoch

Epoch

uint32

10

eventtime

Time when event occured

uint64

20

event_id

Unique event ID

uint32

10

from

Where call was originated from

string

128

kind

Kind of service. Typically it will have value "call"

string

10

level

Log Level

string

11

logid

Unique Log ID

string

10

message_type

Message Type. Ex: message_type="request"

string

16

policy_id

Name of the firewall policy governing the traffic which caused the log message.

uint32

10

profile

Name or number of associated VOIP profile

string

64

proto

Protocol number. Ex: for SIP it will be proto=17

uint8

3

reason

Reason. Ex: reason="unrecognized-form"

string

128

request_name

Name of request. Ex: request_name="INVITE" or "NOTIFY"

string

64

session_id

Session ID. Ex: session_id=232

uint32

10

srcip

IP address of the traffic's origin. Ex: srcip=10.1.100.155

ip

39

src_int

Name of the source interface. Ex: src_int="port1"

string

16

src_port

Port number of the traffic's origin. Ex: srcport=40772

uint16

5

status

Status. Ex: status="blocked" , status= "start"

string

23

subtype

Subtype

string

20

time

Hour clock when the log message was recorded.

string

8

to

Destination address

string

512

type

Type of log. Ex: type="utm"

string

16

tz

Time zone

string

5

vd

Name of the virtual domain in which the log message was recorded.

string

32

voip_proto

SIP/SCCP/MGCP/h323

string

4

44033 - LOGID_EVENT_VOIP_SIP_BLOCK

44033 - LOGID_EVENT_VOIP_SIP_BLOCK

Message ID: 44033

Message Description: LOGID_EVENT_VOIP_SIP_BLOCK

Message Meaning: VoIP SIP blocked

Type: VoIP

Category: VOIP

Severity: Notice

Log Field Name

Description

Data Type

Length

action

Action. Eg. block , allow

string

15

call_id

Ex: call_id="1-22011@10.6.30.11"

string

64

count

Session count

uint32

10

date

Day, month, and year when the log message was recorded.

string

10

devid

Serial number of the device for the traffic's origin.

string

16

dir

Destination Interface

string

16

dstip

Destination IP

ip

39

dst_int

Destination Interface

string

16

dst_port

Destination port

uint16

5

duration

Duration of the session. Ex: 180 (in seconds)

uint32

10

epoch

Epoch

uint32

10

eventtime

Time when event occured

uint64

20

event_id

Unique event ID

uint32

10

from

Where call was originated from

string

128

kind

Kind of service. Typically it will have value "call"

string

10

level

Log Level

string

11

logid

Unique Log ID

string

10

message_type

Message Type. Ex: message_type="request"

string

16

policy_id

Name of the firewall policy governing the traffic which caused the log message.

uint32

10

profile

Name or number of associated VOIP profile

string

64

proto

Protocol number. Ex: for SIP it will be proto=17

uint8

3

reason

Reason. Ex: reason="unrecognized-form"

string

128

request_name

Name of request. Ex: request_name="INVITE" or "NOTIFY"

string

64

session_id

Session ID. Ex: session_id=232

uint32

10

srcip

IP address of the traffic's origin. Ex: srcip=10.1.100.155

ip

39

src_int

Name of the source interface. Ex: src_int="port1"

string

16

src_port

Port number of the traffic's origin. Ex: srcport=40772

uint16

5

status

Status. Ex: status="blocked" , status= "start"

string

23

subtype

Subtype

string

20

time

Hour clock when the log message was recorded.

string

8

to

Destination address

string

512

type

Type of log. Ex: type="utm"

string

16

tz

Time zone

string

5

vd

Name of the virtual domain in which the log message was recorded.

string

32

voip_proto

SIP/SCCP/MGCP/h323

string

4