Cisco Cisco Firepower Management Center 2000 Guía Del Desarrollador

Descargar
Página de 726
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
586
Understanding Legacy Data Structures
Legacy Connection Data Structures
Appendix B
The following diagram shows the format of a Connection Statistics data block for 
4.10.2.x:
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11
1
2
1
3
1
4
1
5
1
6
1
7
1
8
1
9
2
0
2
1
2
2
2
3
2
4
2
5
2
6
2
7
2
8
2
9
3
0
3
1
Connection Data Block Type (125)
Connection Data Block Length
Initiator IP Address
Responder IP Address
Initiator Port
Responder Port
First Packet Timestamp
Last Packet Timestamp
Connection Type
NetFlow Src TOS
NetFlow Dst TOS
NetFlow SNMP Input
NetFlow SNMP Input 
cont.
NetFlow SNMP Output
Source Device IP 
Address
Source Device IP Address cont.
TCP Flags
Packets Sent
Packets Received
Bytes Sent
Bytes Received
Protocol
Server ID...
Server ID, cont...
Client App Type ID
Client Application 
Type ID cont....
Client App ID
Client 
Ap
p V
er
sion
Client Application ID 
cont....
String Block Type (0)
Block Type cont.
String Block Length
String Block Length
Client Application Version...
Client  App URL
String Block Type (0)
String Block Length
Client Application URL...