Logged connections

Logged connections are network connections that

  • are automatically saved to the Cloud-Delivered Firewall Management Center database as end-of-connection events,

  • generate logs regardless of other logging configurations unless connection event storage is disabled, and

  • include connections associated with intrusions, file and malware events, intelligent application bypass, and monitored traffic.

Connection types and logging behavior

The system automatically logs specific connection types based on their association with security events and traffic monitoring.

Connection types that generate automatic logs:

  • Connections associated with intrusions: The system automatically logs connections associated with intrusion events, unless the connection is handled by the access control policy's default action.

  • Connections associated with file and malware events: The system automatically logs connections associated with file and malware events.

  • Connections associated with intelligent application bypass: The system automatically logs bypassed and would-have-bypassed connections associated with IAB.

  • Monitored connections: The system always logs the ends of connections for monitored traffic, even if the traffic matches no other rules and you do not enable default action logging.

Note

File events generated by inspecting NetBIOS-SSN (SMB) traffic do not immediately generate connection events because the client and server establish a persistent connection. The system generates connection events after the client or server ends the session.

Special behavior for default action connections:

  • When an intrusion policy associated with the access control default action generates an intrusion event, the system does not automatically log the end of the associated connection. Instead, you must explicitly enable default action connection logging.

  • However, if you enable beginning-of-connection logging for the default action, the system does log the end of the connection when an associated intrusion policy triggers, in addition to logging the beginning of the connection.

For more information about monitored connections, refer to Logging for monitored connections.