WatchGuard Technologies SOHO Setting a WatchGuard Security Event Processor log host, Wsep Logging

Page 78

Setting a WatchGuard Security Event Processor log host

The log messages may include time synchronizations between the SOHO and the WatchGuard Key Server, discarded packets for a packet handling violation, duplicate messages, time-outs for attempting to open the WatchGuard Feature Key Server, or return error messages.

Follow these steps to view these log messages:

1With your Web browser, go to the SOHO System Status page

using the Trusted IP address of the SOHO.

For example, if using the default IP address, go to: http://192.168.111.1.

2From the navigation bar on the left side, select Logging.

The Logging page appears and the Event Log is displayed in the lower portion of the page.

Setting a WatchGuard Security Event Processor log host

Setting a remote log host causes log messages to be transmitted to a WatchGuard Security Event Processor server (participating in a WatchGuard Firebox SystemTM solution) preconfigured to accept logs from your SOHO. It has the advantages of saving local resources for other less memory-intensive tasks and puts the log host at the WatchGuard Firebox System site where customer support can examine logs at your request to troubleshoot security problems.

1With your Web browser, go to the SOHO System Status page

using the Trusted IP address of the SOHO.

For example, if using the default IP address, go to: http://192.168.111.1.

2From the navigation bar on the left side, select Logging =>

WSEP Logging.

The WatchGuard Security Event Processor page appears.

78

Image 78
Contents WatchGuard Soho User Guide Page Using this guide Following conventions are used throughout this guideCE Notice Certifications and NoticesFCC Certification Industry CanadaTaiwanese Notice Vcci Notice Class a ITE Declaration of Conformity WatchGuard End-User License Agreement Page User Guide WatchGuard Limited Hardware Warranty User Guide Copyright and Patent Information Table of Contents Your Administrative Options Configuring Virtual Private Networking Page Introduction WelcomeRegistration and Identification Information How does a firewall work?How does a firewall work? Protocol How does information travel on the internet?IP Addresses Port numberServices How does the Soho process this information?Network Address Translation NAT Default Factory Settings Soho Home Page-System StatusResetting a Soho to the Factory Defaults Firewall SettingsRebooting a WatchGuard Soho Base Model SohoRebooting a WatchGuard Soho Rebooting a WatchGuard Soho Pre-installation checklist Before you beginInstallation Process Microsoft Windows 95 or 98 or ME Determine your current TCP/IP settingsMicrosoft Windows NT or MacintoshDisable your browser’s Http proxy Exit the TCP/IP configuration screenNetscape Netscape 6/6.1Physically connecting your Soho Internet Explorer 5.0/5.5Cabling the Soho for one to four devices Installation Process Cabling the Soho for more than four computers This creates a connection between the Soho and the modem Installation Process Configuring Your External Network Network addressingDouble-click the Network icon TCP/IP Properties dialog box appears Configuring the Soho External network for dynamic addressing Configuring the Soho External network for static addressing On your computerOn the Soho ExternalConfiguring the Soho external network for PPPoE From the Configuration Mode drop list, select PPPoE Client Click Automatically restore lost connections Release and renew the IP configuration Configuring Your Trusted Network Configure the Trusted network with static addressesRoutes Configure additional computers to the trusted network Configuring Static Routes View the Network Statistics Network Statistics View the Network Statistics Your Administrative Options System SecuritySetting a System Administrator Name and System Passphrase = System Security Setting up VPN Manager Access = VPN Manager AccessClick the Submit button Update Your Configuration from a Non- Windows Platform Redeeming your Soho upgrade certificates= Update = Upgrade Upgrade certificates Seat LicensesView the Configuration File = View Configuration FileView the Configuration File Firewall settings Configuring Incoming and Outgoing ServicesPre-configured Services Incoming or OutgoingCreating a Custom Service Custom Service TCP and UDP PortsIP Protocols Blocking External Sites Blocked Sites Firewall Options Firewall OptionsPing requests received on the External Network Denying FTP access to the Trusted Network interface Socks implementation for the SohoConfigure your Socks application Logging all allowed outbound traffic Disabling Socks on the SohoCreating a virtual DMZ DMZCreating a virtual DMZ Creating a virtual DMZ What is Logging? Viewing Soho log messagesSetting a WatchGuard Security Event Processor log host Wsep LoggingOur example Setting a Syslog Host Syslog LoggingSetting the System Time System TimeIf you have decided to use the WatchGuard Time Server Setting the System Time Setting the System Time WatchGuard Soho WebBlocker How WebBlocker worksWatchGuard WebBlocker database unavailable Web site not in WebBlocker databaseWeb site in WebBlocker database WebBlocker Users and GroupsPurchasing and enabling Soho WebBlocker Bypassing the Soho WebBlockerConfiguring the Soho WebBlocker Enable WebBlockerSettings Enter the Inactivity Timeout in minutes Create WebBlocker Groups and Users GroupsTo the right of the Users field, click the New button Click the Submit button WebBlocker categories Alcohol/TobaccoDrug Culture Search Engines Searching for blocked sites Click Check if the URL is on the CyberNOT ListConfiguring Virtual Private Networking Why create a virtual private network?What you will need IP Address Table example Enabling the VPN upgrade Step-by-step instructions for configuring a Soho VPN tunnelObtaining the VPN upgrade Special considerationsFrequently asked questions Why do I need a static external address?How do I get a static external IP address? How do I connect three or four offices together? OK, why is ping not working?How do I obtain a VPN upgrade certificate? How do I troubleshoot the connection?How do I enable a VPN Tunnel? Muvpn ClientsView the VPN Statistics View the VPN Statistics 104 Troubleshooting How do I reboot my SOHO?General What do the on and Mode lights signify on the SOHO? How do I register my SOHO?Cant get a certain Soho feature to work with a DSL modem Set a password on my unit, but I forgot it. Can you help?What is a Soho feature key? How does the seat limitation on the Soho work?How do I install a Soho using a Macintosh? How can I see the MAC address of my SOHO? ConfigurationWhere are the Soho settings stored? How do I change to a Dhcp trusted IP address?How do I set up and disable Webblocker? How do I change to a static trusted IP address?WebBlocker IncomingVPN Management How do I set up my Soho for VPN Manager Access? How do I set up VPN between two SOHOs?Online Documenting and In-Depth FAQs Contacting Technical supportSpecial Notices Database WebBlocker Default gateway 98 DNS service 116 User Guide 117 Socks