The event auditing function does not support cross-day query. If the query period spans a day or the query start time is later than the end time, the end time will automatically change to 23:59 of the same day as the start time.

Inter-zone access log auditing

Configuration guide

From the navigation tree of the firewall management component, select Inter-Zone Access Logs under Event Auditing to enter the inter-zone access log auditing page, as shown in Figure 51.

A zone is a set consisting of one or more network segments. Inter-zone access logs are logs recorded by the firewall device when network segments of security zones are attacked. Inter-zone access log auditing is for analysis of such logs. Each log records the time when the attack occurred, the attack's source zone, destination zone, source IP:port, destination IP:port, attack protection rule ID, protocol, and action taken by the system, helping you know about the inter-zone access status of the network.

Figure 51 Inter-zone access log auditing

Abnormal traffic log auditing

Configuration guide

From the navigation tree of the firewall management component, select Abnormal Traffic Logs under Event Auditing to enter the abnormal traffic log auditing page, as shown in Figure 52. This page lists the logs in order of time, with the most recent log at the top. Each log records the time, source IP, and destination IP of the abnormal traffic, reason for giving the alarm, severity, and ratio of each protocol used by the abnormal traffic.

Abnormal traffic log auditing allows you to query abnormal traffic logs by source IP, destination IP, reason, severity level, time, and device group, helping you analyze traffic for abnormal behaviors.

52

Page 56
Image 56
HP Firewall manual Inter-zone access log auditing, Abnormal traffic log auditing

Firewall specifications

HP Firewall, often positioned as a key component in enterprise network security, is designed to protect sensitive data and maintain secure communications across various environments. The primary role of a firewall is to monitor incoming and outgoing network traffic and make decisions based on a set of security rules. HP Firewalls utilize a combination of hardware and software to create a robust security framework that helps organizations manage their network perimeter effectively.

One of the main features of HP Firewall is its advanced security protocols that provide deep packet inspection. This technology scrutinizes packet contents beyond the header information, analyzing data flows for signs of malicious activity. By employing Stateful Inspection, HP Firewalls maintain a state table that logs active connections, allowing the firewall to evaluate packets in the context of established sessions. This helps optimize resource usage while delivering high-performance security.

Another characteristic of HP Firewall is its integration with HP's broader security ecosystem. By working seamlessly with other HP security products, such as HP Secure Access and HP Advanced Malware Protection, organizations can deploy a multi-layered security strategy. This integration enables centralized management, streamlining security policies and improving response times against threats.

HP Firewalls also feature next-generation capabilities. This includes intrusion prevention systems (IPS) that actively monitor network traffic for suspected threats and automatically take action to block potential breaches. Additionally, these firewalls come with application awareness features, allowing organizations to enforce policies based on specific applications rather than simply based on port or protocol. This granularity enhances control over minimal use of bandwidth while simultaneously mitigating risks from unwanted applications.

Furthermore, HP Firewall models are equipped with user identity management, allowing organizations to apply security policies based on user roles and the specific needs of the business. This significantly improves the overall security posture as it adds another layer of control.

Scalability is a notable characteristic of HP Firewalls, making them suitable for both small businesses and large enterprises. Organizations can expand their security infrastructure as needed while maintaining efficiency.

In summary, HP Firewalls deliver advanced security features, scalability, and seamless integration within the HP security ecosystem. Their emphasis on deep packet inspection, real-time monitoring, and user identity management make them a powerful asset in the defense against cyber threats, ensuring that organizations can protect their critical data and maintain the integrity of their network environments.