Cisco Cisco Firepower Management Center 2000 Guida Dello Sviluppatore

Pagina di 726
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
352
Understanding Discovery & Connection Data Structures
Host Discovery and Connection Data Blocks
Chapter 4
List Block 
Length
uint32
Number of bytes in the list, including the list 
header and all encapsulated MAC Address data 
blocks.
Host MAC 
Address Data 
Blocks
uint32
Host MAC Address data blocks describing a 
host MAC address. See 
 on page 297 for a description of this data 
block.
Host Last 
Seen
uint32
UNIX timestamp that represents the last time 
the system detected host activity.
Host Type
uint32
Indicates the host type. The following values 
may appear:
• 0 — host
• 1 — router
• 2 — bridge
• 3 — NAT device
• 4 — LB (load balancer)
Mobile
uint8
True-false flag indicating whether the host is a 
mobile device.
Jailbroken
uint8
True-false flag indicating whether the host is a 
mobile device that is also jailbroken.
VLAN 
Presence
uint8
Indicates whether a VLAN is present:
• 0 — Yes
• 1 — No
VLAN ID
uint16
VLAN identification number that indicates 
which VLAN the host is a member of.
VLAN Type
uint8
Type of packet encapsulated in the VLAN tag.
VLAN Priority
uint8
Priority value included in the VLAN tag.
String Block 
Type
uint32
Initiates a String data block for the host client 
application data. This value is always 112.
String Block 
Length
uint32
Number of bytes in the String data block, 
including eight bytes for the string block type 
and length fields, plus the number of bytes in 
the host client application data. 
Host Profile Data Block 5.2+ Fields (Continued)
F
IELD
D
ATA
 T
YPE
D
ESCRIPTION