
M O N I T O R I N G T R A F F I C
7
7-4
User Guide
Setting Up the Logging Infrastructure
Use the following commands in
Table 7-3
to create logs that report specified incidents for the
network manager to review. For details about CLI commands, see the
CLI Command Reference
Guide that comes with your Freedom9 appliance.
Table 7-3: Commands to Set Up the Logging Infrastructure
Setting Up Policies
Policies are set up to specify which traffic is allowed and what actions to take under certain cir-
cumstances. A policy is a set of rules that determines how traffic passes between security zones
(inter-zone policy), between interfaces bound to the same zones (intra-zone policies), and
between addresses in the Global zone (Global addresses).
For example, to allow traffic to pass from one security zone to another, you must configure a
policy that permits zone A to send traffic to zone B. To allow traffic originating in zone B to flow
set alert aggr-bandwidth "ab-user-alert2"
threshold 10000 action log always
Creates an alert that will trigger when
bandwidth usage reaches 10 Mbps. A log
is generated every time this happens.
Command
Description
set syslog enable
Enables sending log messages to a syslog
server.
set syslog config 192.168.65.199
Specifies the IP Address of the syslog
server. This setting should be your log
server address.
The appliance supports two syslog
servers. The second server can be
configured using the same command.
set log module policy level notification
destination syslog
Sends log messages that match the level
"notification" for policy module to the
syslog destination.
set log module session level notification
destination syslog
Sends log messages that match the level
"notification" for session module to the
syslog destination.
set log module policy level notification
destination internal
Sends log messages that match the level
"notification" for policy module to the
internal destination.
set log module session level notification
destination internal
Sends log messages that match the level
"notification" for session module to the
internal destination.
get log messages
Displays log contents.
Example of a displayed log message:
Oct 09 15:58:38 2007 Freedom9
id=fsl100 policy[185] [NOTICE]
BW_AGGR_ALERT: alert id 5 for alert <ab-
user-alert1> generated for policy : 1 from
srcIp/srcPort: 69.66.193.246/17411 to
destIp/destPort: 192.168.65.149/80
protocol: TCP
Summary of Contents for freeGuard Slim 100
Page 10: ...FSL100 User Guide x ...
Page 24: ...G E T T I N G ST A R T E D 1 1 14 User Guide ...
Page 42: ...SY S T E M M A NA G E M E N T 2 2 18 User Guide ...
Page 50: ...M A N A G I N G T R A F F IC F L O W 3 3 8 User Guide ...
Page 58: ...C O N F IG U R I N G A TT A C K PRE VE N T I O N 4 4 8 User Guide ...
Page 84: ...T R A F F I C F LO W R E P O R T I N G 5 5 26 User Guide ...
Page 122: ...M O N I T O R I N G T R A FF I C 7 7 16 User Guide ...
Page 134: ...U SI N G S N M P 8 8 12 User Guide ...
Page 166: ...A L PH AB E T I C LI S T I NG OF LO G M E SS AG E S C C 4 User Guide ...
Page 170: ...N O TI F I C A T I O N A N D S A F E T Y ST A TE M E N T S Battery Statement D D 4 User Guide ...