WatchGuard Technologies FireboxTM System 4.6 manual Replaying a log file, HostWatch display

Models: FireboxTM System 4.6

1 170
Download 170 pages 21.61 Kb
Page 109
Image 109

HostWatch

The HostWatch display uses the logging settings configured for your Firebox using the Policy Manager. For instance, to see all denied attempts at incoming Telnet in HostWatch, configure the Firebox to log incoming denied Telnet attempts.

The line connecting the source host and destination host is color-coded to display the type of connection being made. These colors can be changed. The defaults are:

Red – The connection is being denied.

Blue – The connection is being proxied.

Green – The connection is using network address translation (NAT).

Black – The connection falls into none of the first three categories.

Representative icons appear next to the server entries for HTTP, Telnet, SMTP, and FTP.

Name resolution might not occur immediately when you first start HostWatch. As names are resolved, HostWatch replaces IP addresses with host or usernames, depending on the display settings. Some machines might never resolve, and the IP addresses remain in the HostWatch window.

To start HostWatch, click the HostWatch icon (shown at left) on the

Control Center QuickGuide.

HostWatch display

The upper pane is split into two sides, Inside and Outside. Double-click an item on either side to produce a pop-up window displaying detailed information about current connections for the item. The Connects For window displays the IP addresses, port number, connection type, direction, and other detailed information about these connections.

The lower pane displays detailed information for connections directly related to the Firebox. Double-click a connection to view details regarding a specific host.

Connecting to a Firebox

From HostWatch:

1Select File => Connect.

You can also click the Firebox icon.

2Use the Firebox drop list to select a Firebox.

You can also type the Firebox name or IP address.

3Enter the Firebox read-only password. Click OK.

HostWatch connects to the Firebox and begins the real-time display.

Replaying a log file

You can replay a log file in HostWatch in order to troubleshoot and retrace a suspected break-in. From HostWatch:

1Select File => Open.

You can also click the Folder icon. The Open dialog box appears.

User Guide

99

Page 109
Image 109
WatchGuard Technologies FireboxTM System 4.6 manual Replaying a log file, HostWatch display, Select File = Connect