CHAPTER 14 Monitoring Firebox Activity

An important part of an effective network security policy is the monitoring of network events. Monitoring enables you to recognize patterns, identify potential attacks, and take appropriate action. If an attack occurs, the records kept by WatchGuard will help you reconstruct what happened.

The extensive logging provided with the Firebox System can also be useful in debugging network services, solving routing problems, and identifying other network configuration problems.

Firebox Monitors and HostWatch are two tools for monitoring traffic through the Firebox.

Firebox Monitors

Firebox Monitors is a user interface providing several real-time displays of activity through the Firebox.

Starting Firebox Monitors and connecting to a Firebox

From Control Center:

1On the QuickGuide, click the Firebox Monitors button (shown at

right).

Firebox Monitors opens and displays the Bandwidth Meter tab. There is no active connection to a Firebox.

2Select File => Connect. Or, on the Firebox Monitors toolbar, click Connect.

3Enter a Firebox name or IP address, or use the Firebox drop list to select a Firebox.

Enter the monitoring (read-only) pass phrase. Click OK.

Firebox Monitors displays traffic patterns on the selected Firebox.

User Guide

93

Page 103
Image 103
WatchGuard Technologies FireboxTM System 4.6 manual Monitoring Firebox Activity