Hey all,
Can someone assist me with understanding what this particular ‘firewall,info’ log is indicating or saying from a technical perspective?
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
97
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
102
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
64
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
164
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
80
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
64
11:41:09 firewall,info input: in:ether8 out:(unknown 0), connection-state:established src-mac <remote-mac-omitted>, proto 47, <remote-ip-omitted>-><local-ip-omitted>, len
80
This is a local RB4011iGS+ router that’s getting spammed with these same logs (the src-mac is all the same, and src/dst IPs are all the same, omitted for privacy). This is a GRE tunnel between this local router and a remote CCR1036-8G-2S+. I don’t want to include a ton of info here as all I’m looking for is to understand the log entry itself, but for information’s sake: The GRE tunnel remains up solidly (it’s not incrementing down/up events), OSPF is running stable over the GRE tunnel (no hits either), and pinging with large packets over the tunnel shows no packet loss.
Thanks in advance. ![]()