WANGUARD 5.2 User Manual & Administrator's Guide
IP Zone Configuration
IP Zones
are hierarchical, tree-like structures that must include your IP address ranges and important IPs.
Add an IP Zone by going to Confguraton » Network & Policy » Add IP Zone. Sensors use IP Zones to learn about
your network and to extract per-subnet setngs. An IP Zone may be used by multple Sensors, but a Sensor can only
use one IP Zone.
To change the name of an IP Zone you must frst open the IP Zone Confguraton window, provide a new
descripton and then press <<Change Name>>.
To copy the selected IP Zone you must click the <<Duplicate>> buton. A new IP Zone will be created and it
will have the same informaton and the same descripton with the word “(copy)” atached. In some cases when you
have multple Sensor systems, you may have to create multple IP Zones that share the same prefxes. Instead of
recreatng the same IP classes for each new IP Zone you can duplicate an existng IP Zone and modify only few
parameters.
To delete an IP Zone you must frst open the IP Zone Confguraton window, press <<Delete>> buton and
then confrm the deleton.
The IP Zone Confguraton window is divided in two vertcal sectons. In the upper side of the lef secton
there are butons to manage Prefxes (IP address ranges or individual IPs). When adding a new Prefx, the tree below
is automatcally updated. The right secton contains panels with user-provided setngs for the selected Prefx.
WANGUARD understands IPs and IP classes entered in the CIDR notaton. To enter individual hosts in IP
Zones you must use the /32 CIDR for IPv4 and /128 for IPv6. For more about CIDR notaton you can consult the
Appendix 1 – Network Basics You Should Be Aware Of on page 60.
Every IP Zone contains at least the 0.0.0.0/0 network. Because it has the /0 CIDR it contains all IP addresses
available for both IPv4 and IPv6. To ease the confguraton, every new Prefx that you defne, inherits by default the
propertes of the closest (having the biggest CIDR) IP class that includes it.
The
IP Setngs
panel on the right secton contains the following confgurable parameters:
●
IP Group
combo box should contain a short descripton for the selected Prefx. Setng the same IP
Group for more than one subnet will allow you to easily generate combined Reports.
●
IP Graphs
. If set to “Yes”, then the Console will collect graphs data for every IP contained in the selected
IP class.
●
IP Accountng
. If set to “Yes”, then the Console will save daily accountng data for every IP contained in
the selected IP class.
Enabling IP Graphs and IP Accountng for very large Prefxes (e.g. 0.0.0.0/0) is probably going to generate
useless data and overload the system.
The
Comments
panel allows you to write a comment for the selected Prefx. It's not visible elsewhere.
- 40 -
Summary of Contents for Wanguard 5.2
Page 1: ......