WANGUARD 5.2 User Manual & Administrator's Guide
•
View Trafc Graph
– available if IP Graphs is enabled for the prefx
•
View Trafc Log
– available if the Response contains a Trafc Capturing acton
•
Delete BGP Route
– available if a BGP announcement was sent for the prefx
•
Set Comment
– add or modify comments
•
Stop Trafc Anomaly
– force the Sensor to clear the anomaly
Dropped
The percent of the anomalous trafc fltered by one or more Filter systems.
Severity
The severity feld represents graphically the rato between the anomalous trafc and the threshold
value. Every bar represents 100% of the threshold value.
The color of the severity indicates the link's severity: 0-25% blue, 25%-50% yellow, 50%-75% orange,
75%-100% red. The link's severity is the rato between the anomaly trafc and the overall trafc of the
link (Sensor or Interface).
The exact rule's severity and link's severity is displayed as a tool-tp.
PARAMETERS VISIBLE ONLY WHEN DISPLAY IS SET TO “FULL”
Total Pkts
The number of packets from the total trafc during the anomaly.
Total Bits
The number of bits from the total trafc during the anomaly.
Overall Trafc
The percent between the anomaly trafc and the overall trafc.
Threshold
The threshold's value.
IP Zone
The IP Zone of the Sensor. Click it to open the Prefx setngs from the IP Zone.
Template
The Thresholds Template that contained the anomaly's rule, if any.
Expiraton
The number of seconds between the latest alarm and the tme the anomaly becomes inactve.
Response
The name of the Response executed for the anomaly.
Comments
User comments. The feld is hidden if there are no comments.
If one or more Filters are actvated to detect atackers and atack paterns then a new table will show up in
the same trafc anomaly row. The rows in the table will have red background for actve atack paterns and yellow
background for inactve atack paterns.
Filter
The name of the Filter that detected the atack patern.
Filtering Rule
The fltering rule applied to drop the atack patern's trafc. The Filter dynamically applies the
following fltering rules:
Source IP, Source Port, Destnaton Port, Packet Length, TimeToLive, IP
Protocol.
Filtering rules are applied only when the fltering policy allows dropping of trafc. If the flter conficts
with the Filter's Whitelist, then a red exclamaton point shows up.
- 8 -
Summary of Contents for Wanguard 5.2
Page 1: ......