Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

28721 - LOGID_APP_CTRL_SSH_BLOCK

28721 - LOGID_APP_CTRL_SSH_BLOCK

Message ID: 28721

Message Description: LOGID_APP_CTRL_SSH_BLOCK

Message Meaning: Application control IM (SSH) (block)

Type: APP-CTRL

Category: signature

Severity: Warning

Log Field Name

Description

Data Type

Length

vrf

Virtual Routing Forwarding

uint16

3

vd

Virtual domain name

string

32

user

User name

string

256

unauthusersource

Unauthenticated user source

string

66

unauthuser

Unauthenticated user

string

66

tz

string

5

type

Log type

string

16

time

Time

string

8

subtype

Log subtype

string

20

srcport

Source Port

uint16

5

srcip

Source IP

ip

39

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcintf

Source Interface

string

64

srcdomain

string

255

srccountry

string

64

sessionid

Session ID

uint32

10

service

Service name

string

80

proto

Protocol number

uint8

3

profiletype

Profile Type

string

36

profile

string

36

policyid

Policy ID

uint32

10

logid

Log ID

string

10

level

Log level

string

11

group

User group name

string

512

fctuid

FortiClient User ID

string

32

eventtype

App Control Event Type

string

32

eventtime

Event Time

uint64

20

dstport

Destination Port

uint16

5

dstip

Destination IP

ip

39

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstintf

Destination Interface

string

64

dstcountry

string

64

direction

Direction of the packets

string

8

devid

Deivce ID

string

16

date

Date

string

10

authserver

Authentication server for the user

string

64

applist

Application Control profile name

string

64

appcat

Application category name

string

64

app

Application name

string

96

action

The status of the session: pass - Application is allowed block - Application is blocked (silent) reject - Quarantine reset - Application is blocked and Reset was sent Sometimes, there is a block page for blocking

string

16

28721 - LOGID_APP_CTRL_SSH_BLOCK

28721 - LOGID_APP_CTRL_SSH_BLOCK

Message ID: 28721

Message Description: LOGID_APP_CTRL_SSH_BLOCK

Message Meaning: Application control IM (SSH) (block)

Type: APP-CTRL

Category: signature

Severity: Warning

Log Field Name

Description

Data Type

Length

vrf

Virtual Routing Forwarding

uint16

3

vd

Virtual domain name

string

32

user

User name

string

256

unauthusersource

Unauthenticated user source

string

66

unauthuser

Unauthenticated user

string

66

tz

string

5

type

Log type

string

16

time

Time

string

8

subtype

Log subtype

string

20

srcport

Source Port

uint16

5

srcip

Source IP

ip

39

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcintf

Source Interface

string

64

srcdomain

string

255

srccountry

string

64

sessionid

Session ID

uint32

10

service

Service name

string

80

proto

Protocol number

uint8

3

profiletype

Profile Type

string

36

profile

string

36

policyid

Policy ID

uint32

10

logid

Log ID

string

10

level

Log level

string

11

group

User group name

string

512

fctuid

FortiClient User ID

string

32

eventtype

App Control Event Type

string

32

eventtime

Event Time

uint64

20

dstport

Destination Port

uint16

5

dstip

Destination IP

ip

39

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstintf

Destination Interface

string

64

dstcountry

string

64

direction

Direction of the packets

string

8

devid

Deivce ID

string

16

date

Date

string

10

authserver

Authentication server for the user

string

64

applist

Application Control profile name

string

64

appcat

Application category name

string

64

app

Application name

string

96

action

The status of the session: pass - Application is allowed block - Application is blocked (silent) reject - Quarantine reset - Application is blocked and Reset was sent Sometimes, there is a block page for blocking

string

16