WatchGuard Technologies Firebox X manual Session Summary Proxied Traffic

Page 62

Report Sections and Consolidated Sections

Session Summary — Proxied Traffic

A table, and an optional graph, of the top incoming sessions and outgoing sessions. The sessions show in the sequence of the volume of bytes or the number of connections. The format of the session is: client -> server: service. The service shows in all uppercase letters.

HTTP Summary

Tables, and an optional graph, of the top external domains and hosts that users connect to through the HTTP proxy. The domains and the hosts show in the sequence of the byte count or number of connections.

HTTP Detail

Tables for incoming and outgoing HTTP traffic in the sequence of the time stamp. The fields are Date, Time, Client, URL Request, and Bytes Transferred.

SMTP Summary

A table, and an optional graph, of the top incoming and outgoing e-mail addresses in the sequence of the volume of bytes or the number of connections.

SMTP Detail

A table of the incoming and the outgoing SMTP proxy traffic in the sequence of the time stamp. The fields are: Date, Time, Sender, Recipient(s), and Bytes Transferred.

FTP Detail

Tables for incoming and outgoing FTP traffic, in the sequence of the time stamp. The fields are Date, Time, Client, Server, FTP Request, and Bandwidth.

Denied Outgoing Packet Detail

A list of denied outgoing packets, in the sequence of the time. The fields are: Date, Time, Type, Client, Client Port, Server, Server Port, Protocol, and Duration.

Denied Incoming Packet Detail

A list of denied incoming packets, in the sequence of the time. The fields are Date, Time, Type, Client, Client Port, Server, Server Port, Protocol, and Duration.

Denied Packet Summary

In this section there are different tables. Each table shows the data on the host that denied packets. The data has the time of the first and the last try, the type, the server, the port, the protocol, and the number of tries. If there is only one try, the last field has no data.

Denied Service Detail

A list of events in which a user was denied use of a service. This list includes Incoming and Outgoing requests.

WebBlocker Detail

A list of URLs denied because of WebBlocker, in the sequence of time. The fields are Date, Time, User, Web Site, Type, and Category.

Denied Authentication Detail

A list of each denied authentication, in the sequence of the time. The fields are Date, Time, Host, and User.

IPS Blocked Sites

A list of the IPS blocked sites.

56

WatchGuard System Manager

Image 62
Contents WatchGuardSystem Manager User Guide Address Contents Setting Up Logging and Notification Copy the online help system to more computersLogViewer Settings Importing Certificates Microsoft Internet Explorer 5.5Apache Software License, Version 2.0, January WatchGuard Management Server Getting StartedAbout WatchGuard System Manager Log ServerInstalling WatchGuard System Manager About Hardware and Appliance SoftwareLicense Keys Network addressesTrusted interface 1Network IP Addresses Without the FireboxExternal interface Optional interfacesUses 40-bit encryption Software encryption levelsBase StrongSetting Up Your Management Server Putting the Firebox into operation on your networkMaster password Admin passwordAfter Your Installation Installation TopicsWFS appliance software configuration modes Routed configurationDrop-in configuration Use the Quick Setup Wizard during installation Adding secondary networks to your configurationTo add a secondary networks, do one of these procedures Dynamic IP support on the external interfaceEntering IP addresses About slash notationInstalling the Firebox cables Installation Topics Threat responses, alerts, and expert advice Service and SupportLiveSecurity Service Solutions Easy software updatesLiveSecurity Service Broadcasts New from WatchGuard LiveSecurity Service Self Help ToolsBasic FAQs Interactive Support Forum Advanced FAQsKnown Issues Online TrainingWatchGuard Users Group Using the WatchGuard Users ForumWatchGuard Users Forum Online HelpCopy the online help system to more computers Product DocumentationTechnical Support Software requirementsType of Service Web Site Service TimeWe try to supply a solution in a maximum time of four hours HoursTraining and Certification About the WatchGuard System Manager Window Monitoring Your NetworkStarting WatchGuard System Manager From the Windows DesktopDevice Connecting to a FireboxDisconnecting from a Firebox LogDisconnecting from a Server Connecting to a ServerType the password for the Management Server Seeing Information about DevicesBranch Office VPN Tunnels Firebox StatusCertificates Pptp user VPN tunnels Seeing Information on Log ServersMobile user VPN tunnels No exclamation pointMonitoring VPNs Policy Manager About the WatchGuard ToolbarStarting Security Applications Firebox ManagerLog Viewer Quick Setup WizardHostWatch Historical ReportsLog Server collects logs from each WatchGuard Firebox Setting Up Logging and NotificationSetting Up the Log Server WatchGuard Log Server Configuration dialog box appears Configuration Guide for your version of appliance softwareSetting Global Logging and Notification Preferences Type the new log encryption key two times Click OKClick Save Changes or Close Click Save Changes Setting Global Logging and Notification Preferences Types of Log Messages Traffic Alarm Event DiagnosticReviewing and Working with Log Files Traffic log messagesLog File Names and Locations Alarm log messagesDiagnostic log messages Starting LogViewerBrowse to find the log file and click Open LogViewer Settings Changing LogViewer settings with WFS appliance software Click to set the format of the logs to the default colorsUsing LogViewer Select Edit FindPaste the data into any text editor Click File Merge log files Click Browse to find the files to put together Click MergeUsing LogViewer Using LogViewer Generating Reports of Network Activity Creating and Editing ReportsSelect the filter From Historical Reports, click AddType the report name Change the report definition Specifying a Report Time IntervalType the Firebox IP address or host name. Click Add Specifying Report Sections Type the number of items to put in the table Setting Report PropertiesTo consolidate report sections Exporting Reports Using Report Filters Complete the Filter tabsReport Sections and Consolidated Sections When finished, click OKRunning Reports Change the filter propertiesReport Sections and Consolidated Sections Session Summary Proxied Traffic Consolidated sections Report Sections and Consolidated Sections PKI in a WatchGuard VPN Managing Certificates Certificate AuthorityPublic Key Cryptography and Digital Certificates Certificate Authority CA Certificate Managing the Certificate AuthorityFrom the menu, select the correct GWvpn gateway name Management Server CA CertificateGenerate a New Certificate Find and Manage CertificatesPuts back a certificate that was revoked before RevokeReinstate DestroyManaging the Firebox X Edge Firebox Soho Importing CertificatesNetscape Communicator NetscapeManaging the Firebox X Edge or Soho Device Troubleshooting ideasAdministration System StatusFirewall Removing CertificatesSystem security and remote management LoggingSelect File Soho Management Clean up on PC Removing Certificates Appendix a Copyright and Licensing WatchGuard Firebox Software End-User License AgreementWatchGuard System Manager Copyright and Trademarks Licenses OpenSSL LicenseOriginal SSLeay License Apache Software License, Version 2.0, January Licenses Pcre License GNU Lesser General Public License Licenses Licenses Licenses GNU General Public License Licenses Licenses Licenses Sleepycat License Licenses Appendix B WatchGuard File Locations General File LocationsDefault File Locations Quick Setup WizardPolicy Manager for Fireware Appliance Software Firebox System Manager for Fireware Appliance SoftwareHostWatch for Fireware Appliance Software WatchGuard System Manager Policy Manager for WFS Appliance SoftwareFlash Disk Management for WFS Appliance Software Firebox System Manager for WFS Appliance SoftwareHostWatch for WFS Appliance Software LogViewerLog Server User Interface Management ServerWebBlocker Server Historical Reports Log Server for Fireware Appliance SoftwareLog Server for WFS Appliance Software Management Server User Interface Management Server Setup WizardLog Merge WatchGuard Certificate Authority Default File Locations Index Muvpn Wctp 100