Audit-On-Connect

Comma-Separated List of Servers

Includes the names of the audit servers. A comma separates each server name.

Options

The Options section of the configuration file contains any settings needed to control the Connection Monitors, such as enabling logging and identifying the location and name of the log file.

Port

The port you want a connection monitor to use to communicate with the server software. This entry must match the server's configuration, which is 9009.

LogEnable

Typing True turns logging on. Typing False turns logging off.

LogFile

Identifies the log file location and file name.

Password

Add the encrypted password.

DropPXE

Enables you to ignore PXE DHCP requests if using the DHCP Network Connection Monitor or Microsoft DHCP Server Connection Monitor. When the PXE gets a DHCP request, Audit-on- Connect is triggered. When PXE is done and Windows restarts, Audit-on-Connect is triggered once more, not necessarily using the same IP address.

If set to 1, PXE DHCP packets are ignored. If set to 0, they are processed.

Default

The Default section identifies all IP addresses not previously placed in one of the IP range groups.

IPRange

Set to default.

AuditServers

Comma-separated name of the servers.

DistributionMethod

Set to Round Robin or First Available.

47

Page 55
Image 55
Symantec Security Expressions Server manual Options, Default