Cisco Cisco Firepower Management Center 4000 開発者ガイド

ページ / 536
 
4-97
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures
  Host Discovery and Connection Data Blocks
The following table describes the fields of the User Server data block.
IP Range
Specification
Generic List Block Type (31)
Generic List Block Length
IP Address Range Specification Data Blocks*
Port
Protocol
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Table 4-56
User Server Data Block Fields 
Field
Number of 
Bytes
Description
User Server Data 
Block Type
uint32
Initiates a User Server data block. This value is always 
76
.
User Server Block 
Length
uint32
Total number of bytes in the User Server data block, including eight 
bytes for the user server block type and length fields, plus the 
number of bytes of user server data that follows.
Generic List Block 
Type
uint32
Initiates a Generic List data block. This value is always 
31
.
Generic List Block 
Length
uint32
Number of bytes in the Generic List block and encapsulated data 
blocks. This number includes the eight bytes of the generic list block 
header fields, plus the number of bytes in all of the encapsulated 
data blocks.
IP Address Range 
Specification Data 
Blocks
variable
Encapsulated IP Address Range Specification data blocks up to the 
maximum number of bytes in the list block length.
Port
uint16
Port used by the server.
Protocol
uint16
IANA protocol number or Ethertype. This is handled differently for 
Transport and Network layer protocols.
Transport layer protocols are identified by the IANA protocol 
number. For example: 
  •
6
 - TCP
  •
17
 - UDP
Network layer protocols are identified by the decimal form of the 
IEEE Registration Authority Ethertype. For example:
  •
2048
 - IP