SMC Networks SMC6624M manual Using the Event Log To Find Intrusion Alerts

Models: SMC6624M

1 364
Download 364 pages 24.74 Kb
Page 145
Image 145

Using Passwords, Port Security, and Authorized IP Managers To Protect Against Unauthorized Access

Configuring and Monitoring Port Security

full and new intrusions are subsequently added.) The “prior to” text in the record for the third intrusion means that a switch reset occurred at the indicated time and that the intrusion occurred prior to the reset.

To clear the intrusion from port 1 and enable the switch to enter any subse- quent intrusion for port 1 in the Intrusion Log, execute the port-security 1 clear- intrusion-flagcommand. If you then re-display the port status screen, you will see that the Intrusion Alert entry for port 1 has changed to “No”. That is, your evidence that the Intrusion Alert flag has been reset is the Intrusion Alert column in the port status display no longer shows “Yes” for the port on which the intrusion occurred (port 1 in this example). (Executing show intrusion-logagain will result in the same display as above.)

SMC TigerSwitch 10/100(config)# port-security 1 clear- intrusion-flag

SMC TigerSwitch 10/100(config)# show interface

Intrusion Alert on port 1 is now cleared.

Figure 7-11. Example of Port Status Screen After Alert Flags Reset

Using the Event Log To Find Intrusion Alerts

The Event Log lists port security intrusions as:

W MM/DD/YY HH:MM:SS FFI: port 3 — Security Violation

where “W” is the severity level of the log entry and FFI is the system module that generated the entry. For further information, view the Intrusion Log.

From the CLI. Type the log command from the Manager or Configuration level.

Syntax: log <search-text>

For <search-text>, you can use ffi, security, or violation. For example:

Security, and Authorized

Using Passwords, Port

IP

 

 

 

7-25

Page 145
Image 145
SMC Networks SMC6624M manual Using the Event Log To Find Intrusion Alerts, Event Log lists port security intrusions as

SMC6624M specifications

SMC Networks SMC6624M is a robust and versatile managed switch designed to meet the needs of enterprises seeking reliable network solutions. This device features 24 Gigabit Ethernet ports that allow for high-speed data transfer, making it ideal for environments that demand high bandwidth. The SMC6624M is particularly suited for small to medium-sized businesses that require a powerful network backbone to support various applications, including voice, video, and data transmission.

One of the standout features of the SMC6624M is its Layer 2 and Layer 3 switching capabilities, enhancing the flexibility and efficiency of network management. The switch supports VLANs (Virtual Local Area Networks), which allow administrators to segment network traffic for improved security and performance. This capability is essential for organizations looking to optimize their network resources and apply policies that enhance security.

The SMC6624M also integrates advanced Quality of Service (QoS) features, enabling the prioritization of network traffic. This is particularly useful for applications such as VoIP and video conferencing, where maintaining low latency and jitter is crucial for ensuring a seamless user experience. Users can define traffic classes and manage bandwidth allocation, which helps in maintaining the quality of critical applications even during peak usage times.

In terms of connectivity and performance, the SMC6624M includes 4 Gigabit SFP ports, allowing for fiber optic connections to extend network reach and provide flexibility in deployment. The ability to take advantage of high-speed fiber connections means businesses can scale their networks as needed without significant infrastructure changes.

Management options for the SMC6624M are comprehensive. It supports SNMP (Simple Network Management Protocol) for monitoring and managing network performance effectively. Additionally, the switch can be configured using a web-based interface, command-line interface (CLI), or through SNMP, providing flexibility to network administrators with different preferences and expertise.

Furthermore, the SMC6624M is built with a fanless design, which ensures quiet operation and is energy efficient. Its compact form factor and sturdy build make it suitable for installation in various environments, including data centers and office settings.

Overall, the SMC Networks SMC6624M stands out for its combination of speed, flexibility, and management features, making it an excellent choice for businesses looking to enhance their network infrastructure. With a focus on reliability and performance, this managed switch promises to deliver the capabilities that today's modern networks demand.