Cisco Cisco Web Security Appliance S170 사용자 가이드
25-18
Cisco IronPort AsyncOS 7.5.7 for Web User Guide
Chapter 25 Logging
Access Log File
ACL Decision Tags
An ACL decision tag is a field in an access log entry that indicates how the Web Proxy handled the
transaction. It includes information from the Web Reputation filters, URL categories, and the scanning
engines.
transaction. It includes information from the Web Reputation filters, URL categories, and the scanning
engines.
Note
The end of the ACL decision tag includes a dynamically generated number that the Web Proxy uses
internally to increase performance. You can ignore this number.
internally to increase performance. You can ignore this number.
describes the ACL decision tag values.
TCP_DENIED
The client request was denied due to Access Policies.
NONE
There was an error in the transaction. For example, a DNS failure or
gateway timeout.
gateway timeout.
Table 25-6
Transaction Result Codes (continued)
Result Code
Description
Table 25-7
ACL Decision Tag Values
ACL Decision Tag
Description
ALLOW_ADMIN
The Web Proxy allowed the transaction based on
Applications settings for the Access Policy group.
Applications settings for the Access Policy group.
ALLOW_ADMIN_ERROR_PAGE
The Web Proxy allowed the transaction to an IronPort
notification page and to any logo used on that page.
notification page and to any logo used on that page.
ALLOW_CUSTOMCAT
The Web Proxy allowed the transaction based on custom
URL category filtering settings for the Access Policy group.
URL category filtering settings for the Access Policy group.
ALLOW_WBRS
The Web Proxy allowed the transaction based on the Web
Reputation filter settings for the Access Policy group.
Reputation filter settings for the Access Policy group.
BLOCK_ADMIN
The Web Proxy blocked the transaction based on
Applications or Objects settings for the Access Policy
group.
Applications or Objects settings for the Access Policy
group.
BLOCK_ADMIN_CONNECT
The Web Proxy blocked the transaction based on the TCP
port of the destination as defined in the HTTP CONNECT
Ports setting for the Access Policy group.
port of the destination as defined in the HTTP CONNECT
Ports setting for the Access Policy group.
BLOCK_ADMIN_CUSTOM_USER_AGENT
The Web Proxy blocked the transaction based on the user
agent as defined in the Block Custom User Agents setting
for the Access Policy group.
agent as defined in the Block Custom User Agents setting
for the Access Policy group.
BLOCK_ADMIN_IDS
The Web Proxy blocked the transaction based on the MIME
type of the request body content as defined in the Data
Security Policy group.
type of the request body content as defined in the Data
Security Policy group.
BLOCK_ADMIN_FILE_TYPE
The Web Proxy blocked the transaction based on the file
type as defined in the Access Policy group.
type as defined in the Access Policy group.
BLOCK_ADMIN_PROTOCOL
The Web Proxy blocked the transaction based on the
protocol as defined in the Block Protocols setting for the
Access Policy group.
protocol as defined in the Block Protocols setting for the
Access Policy group.