This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

attr_status value

I am examining old confd log offline of a Sophos UTM 9 image. It contains an audit trail of firewall rule changes (packet filter class ). A line with "object_changed" has values"attr_status"0" oldattr_status="1
What does this mean? Does this mean that a rule becomes disabled ? My guess would be status 0 is not active, status 1 is an active firewall rule?



This thread was automatically locked due to age.
Parents
  • I would also think that this is the case.
    But to be sure, I would try it.
    Deactivate/activate a rule and compare the log.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Thanks   yes I tried  that already, thing is current Sophos UTM image logs this differently already, do not see the attr_status anymore. Or if somebody has a older 9.705-3  Sophos UTM image to test with, I can do that test

Reply Children
No Data