background image

 

 

 

 

 

Internet Monitor 

 

 

IM-1000 

 
 
 

 

User’s Manual  

 

Summary of Contents for IM-1000

Page 1: ...Internet Monitor IM 1000 User s Manual ...

Page 2: ... Manual is subject to change without notice and does not represent a commitment on the part of PLANET PLANET assumes no responsibility for any inaccuracies that may be contained in this User s Manual PLANET makes no commitment to update or keep current the information in this User s Manual and reserves the right to make improvements to this User s Manual and or to the products described in this Us...

Page 3: ...tomer service please take a moment to gather the following information Internet Monitor serial number and MAC address Any error messages that displayed when the problem occurred Any software running when the problem occurred Steps you took to resolve the problem on your own Revision User s Manual for PLANET Internet Monitor Model IM 1000 Rev 1 0 November 2006 PartNo EM IM1000v1 ...

Page 4: ... IP 15 2 3 Setting 16 2 4 Date Time 22 2 5 Permitted IPs 23 2 6 Language 24 2 7 Software Update 25 User List Chapter 3 User List 26 3 1 Example 29 IM Management Chapter 4 IM Management 46 4 1 Configure 47 4 2 Authentication 53 4 3 Rule 111 Record Chapter 5 Setting 133 Chapter 6 User 136 Chapter 7 Service 149 7 1 SMTP 153 7 2 POP3 155 7 3 HTTP 157 7 4 IM 159 ...

Page 5: ...ed IP 173 8 3 Intrusion IP 176 Local Disk Chapter 9 Local Disk 179 9 1 Storage Time 180 9 2 Disk Space 181 Remote Backup Chapter 10 Remote Backup 183 10 1 Backup 184 10 2 Browse 193 Report Chapter 11 Report 194 11 1 Storage Report 201 Status Chapter 12 Status 203 12 1 System Info 204 12 2 ARP Table 206 12 3 Record Info 207 12 4 Event Log 209 ...

Page 6: ...tial information records PRODUCT FEATURES Monitor Web Mail SMTP POP3 IM HTTP FTP and TELNET Contents Records the Web mails E mails IM contents MSN Yahoo Messenger ICQ and QQ HTTP browsed web pages FTP downloading and uploading data information and Telnet BBS contents Sniffer or Bridge Mode Deployment Administrator can choose Sniffer or Bridge mode depends on the real network environment Sniffer mo...

Page 7: ... activities according to its IP or MAC address Administrator can easily view the stored records Remote Monitoring Use the web management interface and no software to install Administrator can log in to view the records anytime or anyplace Optimal Storage Space Prompt Provides the optimal storage time and settings in every service depends on daily network flow and service utilization Easy to use We...

Page 8: ... port is connected to other network device Blink to indicates there is traffic on the port Inbound Outbound Orange Steady on indicates the port is connected at 100Mbps speed 1 3 Specification Product Internet Monitor Model IM 1000 Recommend maximum concurrent user 100 Hardware Inbound 1 x 10 100 Based TX RJ 45 Ethernet Outbound 1 x 10 100 Based TX RJ 45 Console 1 x RS 232 DB 9 Hard Disk 160 GB H W...

Page 9: ...AP Remote Backup Browse E Mail Web Mail HTTP IM FTP Telnet Max Department Group 12 User List Black list Logged User White list Ignored User Auto Search User Anomaly Flow Blaster Alarm Enable Blaster Blocking E Mail NetBIOS Alert Notification Co Defense with Core Switch Sub Administrator Max entry 400 Write Access Group Admin Remote Management Remote Monitor Web Management Port Number can be change...

Page 10: ...ed IPs Language Log out and Software Update The IM 1000 is managed by the main system administrator The main system administrator can add or delete any system settings and monitor the system status The other group administrator have no competency to modify the system settings the administrator s name is set by the system main administrator only can monitor the system status ...

Page 11: ...mpetency to read There must be at least one administrator who have the competency to read and write in IM 1000 The default user name and password of system administrator in IM 1000 are admin and admin Privilege The administrator who has the competency to read write can change the system settings monitor the system status to add and cancel other administrators The administrator who has the competen...

Page 12: ...eb UI through HTTPS protocol Download Bandwidth and Upstream Bandwidth The system administrator should set the accurate bandwidth of WAN in order to be the basic operation of IM 1000 Setting Internet Recorder Configuration The system administrator can import or export the system settings or they can also reset the factory setting and format the disk E mail Setting To activate this option the syste...

Page 13: ...example http 172 20 108 172 8080 and https 172 20 108 172 1025 Log Storage Time System administrator can set the log storage time Date Time Synchronize system clock This option can schronize the Date Time in IM 1000 the administrator s PC and the WAN server GMT The international standard time Greenwich Mean Time GMT Daylight saving time Daylight saving time also called DST or Summer Time is the po...

Page 14: ...min window enter te following information Group Admin set group_admin Password enter 12345 Confirm Password enter 12345 In View Groups column select the permitted group record to see Step3 Click OK to login the user or click cancel to delete the new group administrator Add new group admin 13 ...

Page 15: ...n click modify Step2 In Modify admin password or modify group admin password window Enter the following information Password enter admin new Password enter 52364 confirm Password enter 52364 Step3 Click OK to modify the password or click cancel to cancel the setting To change the admin password 14 ...

Page 16: ... server 1 or DNS server 2 Enter Max Downstream Bandwidth and Max Upstream Bandwidth it depends on the applied flow statistics of the user Enable the setting of Ping HTTP and HTTPS function Click OK The interface IP setting Please do not cancel HTTP and HTTPS before setting the Interface IP because it will let the system administrator could not enter the Web UI of IM 1000 15 ...

Page 17: ...Æ Export System setting to client and click the download button at the right place Step2 When it appeared File Download window click Save button and it will show where the file will be saved Click Save button again The settings of IM 1000 will be copied to the appointed directory ...

Page 18: ...Browse button at right place Step2 In Choose File window choose the directory of former saved file in IM 1000 and choose the correct setting then click Open Step3 Click the lower right OK the window will closed Step4 Click the OK inside the confirm dialogue box the setting will import to IM 1000 Confirm the import setting 17 ...

Page 19: ...Æ Internet Recorder ConFiguration select Reset Factory Setting and Format Hard Disk 18 Step2 Click the OK in the lower right it will restore to the factory setting of IM 1000 and format the disk at the same time Select Resect Factory Setting ...

Page 20: ... of the ISP have request to enter in the sender address column Step5 SMTP Server enter the IP address of the delivered e mail in SMTP server Step6 E Mail Address 1 enter the e mail address in the first one position to receive the alarm message Step7 E Mail Address 2 enter the e mail address in the second position to receive the alarm message 19 Step8 Click the lower right OK to set the function of...

Page 21: ...Click Mail Test button to test E Mail address 1 and E Mail address 2 to see if the e mail sending address can receive the current caution message 20 ...

Page 22: ...Step1 In Reboot Internet Recorder Appliance Æ Reboot button Step2 It will show Are you sure to reboot Step3 Click OK to reboot IM 1000 or click Cancel to cancel reboot IM 1000 Reboot the internet recorder appliance 21 ...

Page 23: ... Name Step4 Enter the frquence of the updating time in Update system clock every minutes System time setting Select Synchronize Æ Sync button the system time in IM 1000 will synchronize to the administrator s computer The settings of Set offset hours from GMT and Server IP can be entered with using Assist If the local area execute the daylight saving time then enable the daylight saving time setti...

Page 24: ...ted IPs settings The Permitted IPs setting Complete the Permitted IPs setting If you want the Permitted IPs to be real working then it must be connect from the administrator to the interface of IM 1000 WebUI but the settings of Ping HTTP and HTTPS all must be canceled Before you cancel the interface address of HTTP and HTTPS you have to set the Permitted IPs first or it will not connect to WebUI t...

Page 25: ...2 6 Language Step1 In System Æ Language choose the Language you want then Click OK Select the language version 24 ...

Page 26: ...are and download into the storage disk in IM 1000 Click Browse Æ Choose file select the newest version of the software Click the lower right OK it will running the update Software update It need 3 minutes to update the software and will reboot after updated the system Please do not turn it off off line and exit the web page during the update or it will cause the error in IM 1000 It is recommended ...

Page 27: ...26 Chapter 3 User List This chapter is about the users can be monitored by the IM 1000 It can automatic serch and add the new users and the system administrator can add the lists by himself or herself ...

Page 28: ...ator can export the monitor user list and some related settings to the PC or import these settings into IM 1000 Department Group The administrator can group the users according to the network structure so that he can manage the system more easily ...

Page 29: ... the application environment No Environments Example 1 The company can be divided into several departments and part of the user department settled in different subnet Example 2 Change the user list by import the user list configuration excel list ...

Page 30: ...d into several departments and part of the user department settled in different subnet 29 Step1 In User List Æ Setting set the following settings To set the Department Group depends on the real network deployment Click OK Set the user list ...

Page 31: ...19 0 0 subnet and the IM 1000 will search the new user in the subnet Wait 1 2 minutes until search complete If system administrator want to search users in specific subnet set the search IP range and click search Select the new user to add click New User Click search new user button ...

Page 32: ...Starting to search new user 31 ...

Page 33: ...Example 1 User List Select the new user to add 32 ...

Page 34: ...Complete to add the new user 33 ...

Page 35: ...ser list In System Æ Interface IP if the DNS server set to be the company s internal DNS server then the IM 1000 will also look up the user DNS name correspond to the internal DNS server when searching the user list When the searched PC has been set the PC or DNS name then IM 1000 will use them to apply to user name The user name priorities are PC name Æ DNS name Æ IP or MAC It depends on the sett...

Page 36: ...tment Group select Laboratory Click OK Click User Name of 172 19 1 254 User Name enter Gateway Department Group select Device_Room Select move this user to ignored user list Click OK then the user will be removed to ignored user list Repeat the steps to complete modifying the user list Select the user to modify ...

Page 37: ...Example 1 User List Enter the user information to modify Complete to modify the user information 36 ...

Page 38: ...Example 1 User List Select the user to modify Enter the user information to modify Move the user to ignored user list 37 ...

Page 39: ...Example 1 User List Fig 2 12 Complete to modify all the user list In Ignored user list the system administrator can also select the user to move to logged user list 38 ...

Page 40: ... 139 1 Netmask enter 255 255 255 0 Add a New user to this Department Group select R D Click OK Add a new subnet The Department Group that selected by system administrator which will become the default Department Group in this subnet Step5 Repeat Step 2 to Step 4 until finish to set the user list 39 ...

Page 41: ...Æ Export User List to Client PC Æclick Step2 When it apprear File Download click Save choose the position to save the download file Click Save again The user list settings will be saved in IM 1000 Select the position to save the download file Step3 Use excel to open the user list configuration settings user_set csv and enter the settings to modify ...

Page 42: ...0 10 Hanson 21 3 00 E0 18 25 F4 BC 9 172 19 100 11 Hans 3 00 02 44 8E B7 C7 9 41 How to use the User List The setting of Department Group The User List can set 36 Department Group The name of Department Group The number of Department Group Example 2 User List The first subnet information The first default subnet Group The first range of the subnet The first subnet User List User s IP User Name Use...

Page 43: ...of Department Group Change the 8th Department Group information and the original Customer_Service will change into Support Add the 12th Department Group information and change Group_12 into R D _2 Change the Department Group information from excel 42 ...

Page 44: ...t Group into 9th Department Group Insert a row under the user list in the first subnet and enter the new user information in the row User IP User Name PC Name Logged Ignored User List User MAC User Department Group In the Logged Ignored user information the 0 number represents Ignored the 3 number represents Logged The symbol represents no information in the excel tablet 43 ...

Page 45: ...t basic information under the second subnet user list the range of IP Netmask Default Group Please enter the basic user information under the third subnet User IP User Name PC Name Logged Ignored List User MAC User Department Group There must be one blank row to divide the user list in two subnet 44 ...

Page 46: ...ng Click User List Configuration Æ Import User List from Client PC Æ Browse Step9 In the Choose File window select the modified user list setting then Click Open To import the modified file Step10 Click the lower right OK the user list setting files will import into IM 1000 45 ...

Page 47: ...ce and IM 1000 can also send the IM login notice to user while he she uses the IM software Authentication MIS engineer can request user to pass the IM authentication first or IM 1000 will block the user s IM connection Rule Default Rule Can set the default rule of MSN Yahoo ICQ and QQ Account Rule Can set different rules for every IM account ...

Page 48: ... IM login notice and IM 1000 can also send the IM login notice to user while he she uses the IM software Step1 Select which IM notification to be enabled Step2 In sender column enter the sender name Step3 Fill in the notice content and click OK IM login notice setting 47 ...

Page 49: ...ification about he processed MSN messages or activities after login to MSN Only available in bridge mode ICQ Alert Notification IM 1000 will notice the user by ICQ notification about he processed ICQ messages or activities after login to ICQ Only available in bridge mode Yahoo Alert Notification IM 1000 will notice the user by Yahoo notification about he processed Yahoo messengers or activities af...

Page 50: ...NetBIOS login notification 49 ...

Page 51: ...Login Notice IM Management MSN login notification 50 ...

Page 52: ...ICQ login notification 51 ...

Page 53: ...Login Notice IM Management Yahoo Messnger login notification 52 ...

Page 54: ...e It s kind of remote authentication service of dial in user POP3 Post Office Protocol It s the protocol used for receiving e mails LDAP Lightweight Directory Access Protocol It s a kind of directory access Protocol which combined the authentication mechanism of SMTP POP3 FTP HTTP and RADIUS etc Shared Secret The needed authentiction password which is used for IM 1000 and RADIUS server to process ...

Page 55: ...54 User Distinguished Name It s the needed account used for IM 1000 to process the authetication to LDAP server ...

Page 56: ...Authentication IM Management Authentication message setting User login authentication 55 ...

Page 57: ...ccount passed the authentication then there is no more action of IM authentication The Authentication function must apply to Rule function For exapmle if MIS engineer wants to make rule setting of MSN MIS engineer select Rule Æ MSN Æ Accept Always It means user can use MSN without passing authentication MSN MIS engineer select Rule Æ MSN Æ Authentication passed That means the user s MSN account ne...

Page 58: ...ur built in authentication mode and also support to RADIUS POP3 and LDAP server authentication How to log in authentication interface Open the browser then type http IM 1000 interface auth For example http 192 168 1 1 auth ...

Page 59: ...ternal RADIUS Server authentication Windows 2003 built in authentication Ex 3 POP3 Internal user must pass the IM authentication then he she is allowed to create QQ connection Use external POP3 Server authentication Ex 4 LDAP Internal user must pass the IM authentication then he she is allowed to create ICQ connection Use external LDAP Server authentication These examples used one to one method Fo...

Page 60: ...d to create MSN connection Use the built in user authentication 59 Step1 Add authentication user in Authentication Æ User Set the authentication user Step2 Select IM Management Æ Rule Æ Default Rule Æ Accept Authentication passed and MSN Message not encrypted Click OK Default IM rule setting ...

Page 61: ...en he she must apply the use privilege of MSN from IM authentication management interface The management interface is http IM 1000 interface auth Default setting is http 192 168 1 1 auth Enter the Name and Password Enter the MSN account Click OK Authentication setting 60 ...

Page 62: ...61 Authentication success Step4 User can use the authenticated MSN account and there is no mor authentication to process in the future e Example 1 IM Management ...

Page 63: ...rnal RADIUS Server authentication Windows 2003 built in authentication Deployment of Windows 2003 RADIUS Server Step1 Click Start Æ Control Panel Æ Add Remove Programs select Add Remove Windows Components then it shows the Windows Comonents Wizard 62 s Step2 Select Networking Services then click Detail Windows components wizard ...

Page 64: ...Example 2 IM Management 63 e Step3 Select Internet Authentication Servic Add new network authentication service components ...

Page 65: ...agement 64 Service Service Step4 Click Start Æ Control Panel Æ Administrative Tools select Network Authentication Control Panel Æ Administrative Tools select Network Authentication Select network authentication service ...

Page 66: ...Example 2 IM Management 65 t t Step5 Right click RADIUS Clients Æ New RADIUS Clien Right click RADIUS Clients Æ New RADIUS Clien Add new RADIUS client ...

Page 67: ...Example 2 IM Management Step6 Enter the Name and Client Address It is the same as IM 1000 IP Address Add New RADIUS client name and IP address setting 66 ...

Page 68: ...ter the Shared secret and Confirm Share secret It must be the same setting as RADIUS in IM 1000 Select RADISU Standard enter the Shared secret and Confirm Share secret It must be the same setting as RADIUS in IM 1000 Add new RADIUS client vendor and shared secret ...

Page 69: ...Example 2 IM Management 68 y y Step8 Right click on Remote Access PoliciesÆ New Remote Access Polic Right click on Remote Access PoliciesÆ New Remote Access Polic Add new remote access policies ...

Page 70: ...Example 2 IM Management Step9 Select Use the wizard to set up a typical policy for a common scenario and enter the Policy name Add new remote access policies and policy name 69 ...

Page 71: ...Example 2 IM Management Step10 Select Ethernet The way to add new remote access policy 70 ...

Page 72: ...Example 2 IM Management Step11 Select User Add new romote access policy user and group 71 ...

Page 73: ...Example 2 IM Management Step12 Select MD5 Challenge The authentication of add new remote access policy 72 ...

Page 74: ...Example 2 IM Management Step13 Right click on the Radius Æ Properties The network authentication service setting 73 ...

Page 75: ...Example 2 IM Management Step14 Select Grant remote access permission and Remove the original setting then click Add The RADIUS properties settings 74 ...

Page 76: ...Example 2 IM Management Step15 Add Service Type Add new RADIUS properties attribute Step16 Add Authenticate Only from the left side Add RADIUS properties service type 75 ...

Page 77: ...Example 2 IM Management Step17 Click Edit Profile select Authentication and check Unencrypted authentication PAP SPAP Edit RADIUS service type dial in property 76 ...

Page 78: ...Example 2 IM Management Step18 Add Auth User click Start Æ Setting Æ Control PanelÆAdministrative Tools select Computer Management Enter computer management 77 ...

Page 79: ... Step20 Complete the Windows 2003 RADIUS Server settings Step21 In Authentication Æ RADIUS function enter IP Port and Shared Secret The setting must be the same as RADIUS server The RADIUS server setting Click Test it can detect if the IM 1000 and RADIUS server can real working 78 ...

Page 80: ... passed Default IM rule Step23 If the internal user want to use MSN then he she must apply the use privilege of MSN from IM authentication management interface The management interface is r http IM 1000 interface auth Default setting is http 192 168 1 1 auth Enter the Name and Password Enter the Yahoo account ...

Page 81: ...Example 2 IM Management Authentication setting 80 ...

Page 82: ... Click OK Example 2 IM Management Authenticated successful User can use the authenticated Yahoo account and there is no more authentication to process 81 ...

Page 83: ...ction Use external POP3 Server authentication 82 Step1 Select Accept Authentication passed and QQ Password valid in IM Management Æ Rule Æ Default Rule Æ QQ Set the QQ default rule Step2 Enter the POP3 setting in Authentication Æ POP3 POP3 setting Click Test to see if IM 1000 can connect to POP3 Server properly ...

Page 84: ...of MSN from IM authentication management interface The management interface is http IM 1000 interface auth Default setting is http 192 168 1 1 auth Enter the POP3 Server account name and password It is the mail account and password that used for receiving e mails Enter QQ account Enter the QQ account and password 83 ...

Page 85: ... Click OK 84 QQ account authenticated succeed Step4 User can use the authenticated QQ account and there is no more authentication to process in the future Example 3 IM Management ...

Page 86: ...nal LADP Server authentication Windows 2003 Server built in authentication Windows 2003 LDAP Server Deployment 85 Step1 Click Start Æ Program Æ Administrative Tools Æ Manage MIS engineer Server Step2 In Manage MIS engineer Server window click Add or remove a role Æ Configure MIS engineer Server Wizard Click add or remove a role ...

Page 87: ...Example 4 IM Management 86 t t Step3 In Preliminary Steps window click Nex In Preliminary Steps window click Nex The Preliminary steps Web UI ...

Page 88: ...Example 4 IM Management 87 t t Step4 In Server Role window select Active Directory and click Nex le window select Active Directory and click Nex The server role window ...

Page 89: ...Example 4 IM Management 88 t t Step5 In Summary of Selections window click Nex In Summary of Selections window click Nex The summary of selections window ...

Page 90: ...Example 4 IM Management 89 t t Step6 In Active Directory Installation Wizard window click Nex 6 In Active Directory Installation Wizard window click Nex Active directory installation wizard ...

Page 91: ...Example 4 IM Management 90 t t Step7 In Operating System Compatibility window click Nex g System Compatibility window click Nex The operating system compatibility window ...

Page 92: ...emnt 91 ext Step8 In Domain Controller Type window select Domain controller for a new domain click N In Domain Controller Type window select Domain controller for a new domain click Next The domain controller type window ...

Page 93: ...Example 4 IM Management Step9 In Create New Domain window select Domain in a new forest click Next Create new domain window 92 ...

Page 94: ...Example 4 IM Management Step10 In New Domain Name window enter the Full DNS name for new domain click Next The new domain name window 93 ...

Page 95: ...Example 4 IM Management Step11 In NetBIOS Domain Name window enter the Domain NetBIOS name click Next The NetBIOS domain name window 94 ...

Page 96: ...Example 4 IM Management Step12 In Database and Log Folders window enter the routes of Database folder and Log folder click Next The database and log folder window 95 ...

Page 97: ...Example 4 IM Management Step13 In Shared System Volume window enter the Folder location click Next The shared system volume window 96 ...

Page 98: ...Example 4 IM Management Step14 In DNS Registration Diagnostics window select I will correct the problem later by configuring DNS manually Advanced click Next The DNS registration diagnostics window 97 ...

Page 99: ...Example 4 IM Management Step15 In Permissions window select Permissions compatible only with Windows 2000 or Windows Server 2003 operating systems click Next The permissions window 98 ...

Page 100: ...Management Step16 In Directory Services Restore Mode Administrator Password window enter the Restore Mode Password and Confirm password click Next The directory services restore mode administrator password window 99 ...

Page 101: ...Example 4 IM Management Step17 In Summary window click Next The summary window 100 ...

Page 102: ...Example 4 IM Management Step18 Complete the Active Directory installation wizard Complete the active directory installation wizard 101 ...

Page 103: ...Example 4 IM Management Step19 Click Start Æ Programs Æ Administrative Tools Æ Active Directory Users and Computers Enable active directory users and computers 102 ...

Page 104: ...Example 4 IM Management Step20 In Active Directory Users and Computers window right click on the Users select New Æ User Add new active directory user 103 ...

Page 105: ...Example 4 IM Management Step21 In New Object User window enter the settings click Next The new object user setting window 1 104 ...

Page 106: ...Example 4 IM Management Step22 In New Object User window enter the password click Next The new object user setting window 2 105 ...

Page 107: ...Example 4 IM Management Step23 Complete to add the user Complete to add the user Step24 Select IM Management Æ Default Rule Æ ICQ Æ Accept Authentication passed 106 ...

Page 108: ...The default rule setting of IM 107 ...

Page 109: ...Example 4 IM Management Step25 In Authentication Æ LDAP enter the following setting The LDAP Server setting Click Test it can detect if the IM 1000 and LDAP server can real working 108 ...

Page 110: ...ment Step26 Internal user type http IM 1000 interfac auth in address cloumn of browser For example http 192 168 1 1 auth Enter the authentication name and password Enter ICQ account Click OK ICQ authentication setting 109 ...

Page 111: ...Example 4 IM Management Step27 User can create the ICQ connection after authenticated Authenticated succeed 110 ...

Page 112: ...gineer can separately set the IM rule for every IM account in Account Rule and the IM account will not affected by Default Rule Normal Default Rule For MSN Yahoo ICQ and QQ Accept Always Everyone can freely use the IM account Accept Authentication passed Drop Authentication failed User must to pass the authentication first then he she can use the IM account Drop Always No one can use the IM accoun...

Page 113: ... selected China in Country Region column of MSN personal profile then user can select MSN content encryption function in Activities function Encrypted MSN contents Types of MSN Rule Accept MSN Message not encrypted Drop MSN Message encrypted Anyone can freely use MSN by normal way to send message IM 1000 will block MSN while user send message by encrypt MSN message 112 ...

Page 114: ... Authentication failed or MSN Message encrypted User can use MSN only if the MSN account passed authentication and MSN message not encrypted IM 1000 will block the MSN if MSN not passed authentication or even though MSN passed authentication but its contents encrypted ...

Page 115: ...is http IM 1000 interface qq For example the default setting is http 192 168 1 1 qq Types of QQ Rule Accept QQ Password valid Drop QQ invalid User must type the correct QQ account and password in Add New QQ Account interface then he she can use the QQ account If it s not correct then IM 1000 will block the QQ account Accept Authentication passed and QQ Password valid Drop Authentication failed or ...

Page 116: ...r Account List Configuration Excel list Example IM Management The following QQ examples here are suitable for the internal user who do not have to pass the IM authentication If MIS engineer want to request internal user to pass IM authentication then he she is allowed to use QQ to communicate please refer to the examples 1 or 3 of IM authentication The built in mechanism of authentication for inte...

Page 117: ...ege of QQ messenger from the record in IM 1000 Step1 In Record Æ Service Æ IM there is one QQ record can not be recorded normally Found the QQ account which can t be recorded Click the QQ record it can not correctly shows the QQ message contents IM 1000 can not record QQ message In IM Management Æ Rule Æ Account Rule it shows the uncertificated QQ account 116 ...

Page 118: ...Found the uncertificated QQ account 117 ...

Page 119: ...ccounts in browser enter the string of qq_accounts at the end of IM 1000 interface IP address then it shows the interface of Add New QQ Account Enter Add New QQ Account interface User must enter the QQ ID and password then click Test to see if all of them are correct Test QQ account Click OK to complete the application of QQ account 118 ...

Page 120: ...Add new QQ account successfully 119 ...

Page 121: ...Account the administrator can see all the QQ account list Administrator can not get user s QQ password Password authenticated succeed Step4 IM 1000 can record the QQ contents successfully Can record the QQ contents Record the QQ contents successfully 120 ...

Page 122: ...o apply to modify his her QQ password from IM 1000 Enter the address of http 192 168 1 1 qq_accounts in browser enter the string of qq_accounts at the end of IM 1000 interface IP address then it shows the interface of Add New QQ Account Enter Add New QQ Account interface User must enter the QQ ID original password new password and confirm password Enter the old password password and confirm passwo...

Page 123: ... the IM 1000 will auto complete the QQ account authentication Step4 In IM Management Æ QQ Account the system administrator can see the user s QQ account has certificated Administrator can not get the QQ password QQ account authenticated succeed Step5 IM 1000 can record the QQ message contents Record the QQ message contents successfully 122 ...

Page 124: ...Example 2 IM Management Record the QQ message contents successfully 123 ...

Page 125: ...1 Download the User Account List Configuration file Click Download near Export Account Rule to Client PC in IM Management Æ Rule Æ Default Rule Download the user account list configuration In File Download dialogue box click Save Then assign the saved location and click Save again Select the location to save the rule list 124 ...

Page 126: ...pport 172 19 70 204 00 05 5D 95 5B C6 Yahoo test01 Default support 172 19 70 202 00 0A 48 0C A6 20 USER Yahoo test04 Default support 172 19 70 204 00 05 5D 95 5B C6 POP3 QQ 539236964 Default 172 19 70 203 00 05 5D 95 5B C6 QQ 539330473 Default sales 172 19 50 25 00 0B DC 29 8A CC QQ 539337471 Default sales 172 19 70 203 00 05 5D 95 5B C6 ICQ 292420150 Default 172 19 50 26 00 0A 48 0C A6 20 means t...

Page 127: ... hotmail com Accept sales 172 19 50 24 00 0C 29 8A BB 46 USER To modify the IP and MAC address MSN test01 hotmail com Accept sales 172 19 50 24 00 0C 29 8A BB 46 USER MSN test01 hotmail com Accept sales 172 19 52 30 00 0C 29 8A BC 9A USER If MIS engineer want to add one IM account just add one row and type the related information Yahoo test03 Default 172 19 70 204 00 05 5D 95 5B C6 Complete the mo...

Page 128: ...M accounts in csv file and upload it then the removed IM account still existed MIS engineer does not need to modify the authentication method in csv file It is because if MIS engineer has enabled the IM authentication mechanism then user must set the related IM account information to pass the IM authentication And the IM authentication method is determined by authentication IM account and passowor...

Page 129: ...128 but user can still enter the related POP3 information and pass the IM authentication in IM Management Interface ...

Page 130: ... Icon Name Description Authentication Passed Every IM account has a portrait and that means the IM account is not certificated But if system added an icon of certification near the portrait and that means the IM account is certificated Password Correct It means the applied QQ account and password were passed the authentication and IM 1000 can record the contents of this authenticated QQ account Pa...

Page 131: ...tion Click OK For example select one MSN accout and click To Accept to move the MSN account to Accept Accout Select IM account Confirm to move the account to accept account Step2 Complete to move the IM account to accept account The account has been removed to accept account 130 ...

Page 132: ...d IM Account Step1 Select which IM service to add in IM Service function For example MSN Click Add at the right column in MSN Account of Default Rule Add MSN account of default rule Step2 Enter the related information in the column of Add Account Policy Enter the related information 131 ...

Page 133: ...132 e Step3 Complete to add a MSN account to default rul Complete to add the MSN account of default rule ...

Page 134: ...rator easy to manage all of the information by clearly group department division And assure the data transmission security and monitor the employee s internet activities In other words IM 1000 can prevent the employee to use the network resources to access private activity via internet ...

Page 135: ...record depends on the user s MAC address when it comes from the same MAC address will be decide to be the same user Normally the user s IP is the dynamic IP address The Company uses the DHCP When internal user want to link to the internet by IM 1000 in front of the router the MAC address of packets will be replaced in rounter s MAC address then sent to IM 1000 It s better to use the user name bind...

Page 136: ...o enable the http cache setting as IM 1000 process the http recording Enable HTTP cache IM 1000 can record the browsed web pages by saving the whole web page contents but it also waste more disk space Disable HTTP cache IM 1000 can record the browsed web pages by saving the address links The system administrator only can see the modified web pages if they ve been modified It only waste less disk s...

Page 137: ...tor easy to manage all of the information by clearly group department division And assure the data transmission security and monitor the employee s internet activities In other words IM 1000 can prevent the employee to use the network resources to access private activity via internet ...

Page 138: ...onitor the internet record of the specific User Step1 In RecordÆ User Æ Logged can select the division of user Click subnet or department group Select subnet classification Select department group classification 137 ...

Page 139: ...ee For example use the subnet 172 19 0 0 User of Rayearth it shows the service record The service types of specific user Step3 Click Today Log to know what kind of internet activities has done by the employees Today s record of the user 138 ...

Page 140: ...Example User Step4 click the event to know the content of the internet activites done by the user For example HTTP Can open the http files in IM 1000 139 ...

Page 141: ...has sent by the user in SMTP service The user s SMTP service record Step6 Click the record it will shows e mail contents and forward the mail to the specific mail box And you can choose to open or save the attached file The e mail contents sent by the user 140 ...

Page 142: ... the user in POP3 service The user s POP3 service record Step8 Click the record it shows the e mail contents and users can also forward this e mail to the specific e mail box The user can also choose to open or save the attachment The e mail contents received by the user 141 ...

Page 143: ...Example User Step9 Click HTTP to know which web page did the user browsed The User s HTTP Service Record Step10 Click the record it shows the web page The user s browsed web page 142 ...

Page 144: ...e the conversation with the user Th number at right side represents the frequency of the conversation The user s MSN service record Step12 Click the number of 15 at the right side then it shows the conversatio contents n The user s conversational contents ...

Page 145: ...eb SMTP to know what kind of E Mail has the user sent in Web SMTP The Web SMTP record Step14 Click the recorded subject then it shows the e mail contents and it can be opened or saved The e mail contents sent via the Web SMTP 144 ...

Page 146: ...Step15 Click Web POP3 to know what kind of e mail has the user received in Web POP3 The received record In Web POP3 Step16 Click the Subject it shows the e mail contents The mail contents receieved from Web POP3 145 ...

Page 147: ...uded the attached file but user only read the mail content from Web POP3 records without downloading the attached file Then IM 1000 will only notice the user about the mail has attached file and also its file name 146 ...

Page 148: ...p17 Click FTP to know what kind of files has the user upload or download The user s service record in FTP Step18 Click the record it shows File Download window and choose to open or save Download the file from FTP 147 ...

Page 149: ...mple User Step19 Click TELNET to know which site has the user login The user s record in Telnet service Step20 Click view the content then it shows the contents It shows the contents when user s Log in 148 ...

Page 150: ...ord the e mail receieved by the user through mail server 3 HTTP Record the web page browsed by the user 4 IM Record the communication record of IM For example MSN Yahoo Messenger ICQ QQ 5 Web SMTP Record the the e mail sent by the user through the internet mail box For example Yahoo Gmail Hotmail 6 Web POP3 Record the user s browsed e mail in internet mail box For example Yahoo Gmail Hotmail 7 FTP...

Page 151: ...in the mail attachment we can offer POP3 SMTP WebPOP3 Web SMTP services to search the mail record saved in IM 1000 The function icon is In the SMTP for example 1 Sender enter the key words about e mail account For example julie julie planet com tw 2 Select attach 3 Click Fig 6 1 Search the specific record in SMTP 150 ...

Page 152: ...specific date some key words and characters the administrator can use the FTP service to search the files in IM 1000 We will make some settings in FTP search function 1 User Name Enter js26 2 Size Choose over 1KB 3 Click Search the specific record of FTP 151 ...

Page 153: ...n POP3 and SMTP In other words the records backup function will be more flexible We will add some settings in this function menu 1 Select the record to forward 2 Click forward icon Fig 6 3 Select the record to forward 3 It shows the forward dialogue box enter the sender e mail address Click OK The forwarding mail settings 152 ...

Page 154: ...7 1 SMTP 153 Step1 Click Record Æ Service Æ SMTP it shows SMTP window SMTP Step2 Click Subject to view the e mail contents Fig 6 6 Click the subject in SMTP ...

Page 155: ...Service 154 Step3 It shows the mail contents sent by the user The mail contents sent by the user It can shows the mail contents forward function and the MIS engineer can choose to view or save the attachment ...

Page 156: ...7 2 POP3 155 Step1 Click Record Æ Service Æ POP3 POP3 window Step2 Click Subject to view the mail contents Click the subject in POP3 ...

Page 157: ... Service 156 Step3 It shows the mail contents sent by the user The mail contents sent by the user It shows the mail contents and then forward it On the other hands the attachment also can be viewed or saved ...

Page 158: ...7 3 HTTP 157 Step1 Click Record Æ Service Æ HTTP HTTP Step2 Click Web Site to view Click the web site recored ...

Page 159: ...HTTP Service Step3 It shows the web site record The user s web site record 158 ...

Page 160: ...7 4 IM 159 Step1 Click Record Æ Service Æ IM IM Step2 Click the IM record to view Click the IM record ...

Page 161: ...IM Service 160 Step3 It shows the communication contents The communication contents ...

Page 162: ...7 5 Web SMTP 161 Step1 Click Record Æ Service Æ Web SMTP Web SMTP Step2 Click Subject to view the e mail content Click the subject in Web SMTP ...

Page 163: ...Web SMTP Service Step3 It shows the Web mail content sent by the user The mail content in Web SMTP This window shows the mail content and the user can select to view or save the attachment 162 ...

Page 164: ...7 6 Web POP3 163 Step1 Click Record Æ Service ÆWeb POP3 Web POP3 Step2 Click the Subject to view the mail content Click the subject in Web POP3 ...

Page 165: ...Web POP3 Service 164 Step3 It shows the web mail contents browsed by the user The mail content in Web POP3 It shows the mail content and the user can choose to view or save the attachment ...

Page 166: ...7 7 FTP 165 Step1 Click Record ÆService ÆFTP FTP Step2 Click the FTP record to view Click the FTP record ...

Page 167: ...FTP Service 166 Step3 The user can select to open or save files via the FTP tools To open or save the file ...

Page 168: ...7 8 Telnet 167 Step1 Click Record Æ Service Æ TELNET TELNET Step2 Click the TELNET content to view Click the TELNET record ...

Page 169: ...TELNET Service 168 Step3 It shows the TELNET content The TELNET content ...

Page 170: ...e internal anomaly mount of packets sent from external hackers and also included the mechanism of co defense system can enhance the enterprise network security and stability In this chapter we will make the introduction and settings of Anomaly Flow IP ...

Page 171: ...e sessions of anomaly flow IP Notification IM 1000 can notice the user and system administrator by e mail or NetBIOS notification as any anomaly flow occurred Co Defense System IM 1000 has the co defense mechanism which can integrated the switch so that can enhance the enterprise network security protection Non detected IP System administrator can set which IP address to be the non detected IP it ...

Page 172: ...P The default setting is 100 Session Sec Select Enable Anomaly Flow IP Blocking and set the Blocking Time The default setting is 60 seconds Select Enable E Mail Alarm Notification Select Enable NetBIOS Alarm Notification IP Address of Administrator enter 172 19 100 254 Select enable co defense system and enter the IP address of switch user name and password Click OK Anomaly flow IP setting in IM 1...

Page 173: ...172 Anomaly Flow IP Setting Step2 Set the Non detected IP Click New Entry Enter the IP Address and Netmask Click OK Enter the ip and netmask Complete the setting ...

Page 174: ... detected that there are many intrusion packets it will show the alert message in Virus Infected IP or send NetBIOS alert message to the virus infected user and MIS engineer s PC The alarm message in internal virus infected IP Send the NetBIOS alarm to virus infected PC 173 ...

Page 175: ...174 Anomaly Flow IP Virus Infected IP Send the Net BIOS alarm to the administrator s PC ...

Page 176: ...omaly Flow IP Virus Infected IP If the system administrator select Anomaly Flow IPÆ SettingÆ Enable E Mail Alert Notification the IM 1000 will automatic send the mail to alarm the system administrator 175 ...

Page 177: ...nt show the message at intrusion IP or send NetBIOS alarm notification to the invader and administrator s PC after system has detected there are many intrusion packets from the external computer The notification of intrrusion IP The NetBIOS notification sent to the intrusion IP 176 ...

Page 178: ...177 Anomaly Flow IP Intrusion IP The Net BIOS notification sent to the administrator s PC ...

Page 179: ...8 Anomaly Flow IP Intrusion IP If the system administrator select Anomaly Flow IP Æ Setting Æ Enable E Mail Alert Notification the IM 1000 will automatic send the mail notification to system administrator ...

Page 180: ...er 9 Local Disk MIS engineer can easily know the current disk utilization included disk space and the estimated disk utilization and percentage of 8 services depends on the storage time that MIS engineer had set ...

Page 181: ...ge space and its percentage depends on daily average service flow and storage time Average Size Day The average flows in a day Duration y m d It means the duration of storage time Use A d mode to display include the year month and date For example 06 01 15 06 02 15 Storage Time We can set the storage time depends on the real network usage of the company 0 day means No Recording The storage duratio...

Page 182: ... space Use the mouse point to each color it shows the service name and the 8 recorded services utilization in the storage disk The 8 Recorded Services Utilization It will arrange the TOP 10 users by the service utilization in graphic charts It depends on the 8 recorded services of SMTP POP3 HTTP IM Web SMTP Web POP3 FTP and TELNET 181 ...

Page 183: ...The Storage disk information 182 ...

Page 184: ...mote backup 1 No storage limitation 2 To avoid losing recorded files For example the records be removed by IM 1000 when over the storage time or system make the unpredictable errors 3 MIS engineer can still browse the remote share directory which contain the backup files Please refer to Chapter 7 Service for more information ...

Page 185: ...ific time to process automatic remote backup Backup Immediately MIS engineer can set IM 1000 to backup the record at specific time Browse Setting If the backup directory is fulled then MIS engineer can modify the setting and backup the files to the other directory If MIS engineer want to check the original backup records then he can make the Browse Setting and see the contents of backup directory ...

Page 186: ...185 then he must set the backup folder to be July 2006 in Remote Backup Æ Setting Æ Browse And he can also look up the record in July 2006 in Remote BackupÆ Service ...

Page 187: ...er appliance sends mail notice after backup had completed Set the mail notice setting Step2 To set the backup path Enter the Computer Name IP Enter the name of Shared Directory Enter the login ID for IM 1000 to login Enter the password for IM 1000 to login Set the backup path ...

Page 188: ...the remote shared Co directory To test if IM 1000 can connect to remote backup folder Step4 Select the Service type to backup and also choose the backup time then click OK Select the service to backup and choose backup time If IM 1000 can connect to the remote backup disk then system will show the message in Connection Status of Remote Hard Disk ...

Page 189: ...Connection Status of Remote Hard Disk 188 ...

Page 190: ...189 Remote Backup Setting Step5 The IM 1000 will backup the records to the IP address that MIS engineer had set in Backup Setting Æ Computer Name IP at 00 00 AM Remote shared directory ...

Page 191: ...te Backup Setting To set Backup Immediately Step1 Select the backup time Step2 Select the service type to backup Step3 Click OK Set backup immediately Step4 IM 1000 will send mail notice after backup completed ...

Page 192: ...he files which contain the same service name and date Not every data type of service name is the same For example HTTP includes 3 types of article event and icon Every data type contains 3 extension file name of frm MYD and MYI Assume that MIS engineer want to back up the http records on 11th September 2006 then it will at least contain 9 files 3 data types multiply 3 extension file name http_arti...

Page 193: ...kup im_own_alias_ frm im_own_alias_ MYD im_own_alias_ MYI All data types of every service category Service Name Data Type HTTP article event icon FTP article event IM article article_file event SMTP article event POP3 event event Telnet article event WEB SMTP Ms_article Ms_event Ms_event_att WEB POP3 Mr_article Mr_event Mr_event_att Backup the Shared Directory Remote Backup 192 ...

Page 194: ...er to browse And the way to set Browse Setting is the same as Backup Setting Set the browse setting Step2 MIS engineer can see the record contents saved in remote shared directory in Remote Backup Æ Service after MIS engineer had comp the browse settin leted g ...

Page 195: ...ge disk by the graphic charts It also can mail the statistics report to specific e mail address depends on the administrator s demand The report included three main parts Setting Flow report and Storage report In this chapter we will make the introduction of these three sections ...

Page 196: ...3 The NUS IM 1000 will send the storage report to the recipient when the time arrived 4 In History Report choose the selected date to mail 5 Click Send Report 6 It will mail the related statistics report to the user The way to result the perodic report 1 Yearly Report It results the report at 00 00 AM January yearly 2 Monthly Report It results the report at 00 00 AM of the first day monthly 3 Week...

Page 197: ...The periodic report setting 196 ...

Page 198: ...The storage report 197 ...

Page 199: ...The history report mail setting Receive the history report 198 ...

Page 200: ...The storage report 199 ...

Page 201: ...The IM 1000 will mail the statistics report to recipients by PDF attachment 200 ...

Page 202: ... is displayed in Step1 Hard Disk Utilization The 8 services are record in different colors When the mouse point to the colors it will show the service name and the usage space The hard disk utilization Step2 Today s Utilization it is displayed in Ordinate The service flow its unit is Mbytes Horizontal ordinate The service name The percentage of the service record in hard disk utilization 201 ...

Page 203: ...eport Report Step3 According to the time unit in every service It is displayed in Ordinate The service usage Its unit is Mbytes Horizontal ordinate It represents the Time The storage report of every service 202 ...

Page 204: ...hard disk utilization memory utilization and ram disk utilization 2 ARP Table To record all the host ARP connected to IM 1000 3 Record Info It shows the current 8 services connection information HTTP FTP POP3 SMTP IM TELNET Web Mail 4 Event Log It records every events occurred in IM 1000 such as modify settings anomaly flow alert forward mails delete files and etc ...

Page 205: ...of IM 1000 System Uptime The cumulate time in the IM 1000 until the current time CPU Utilization The CPU utilization in IM 1000 HardDisk Utilization The hard disk utilization in IM 1000 Memory Utilization The memory utilization in IM 1000 RamDisk Utilization The ramdisk utilization in IM 1000 ...

Page 206: ...System Info Status The system info 205 ...

Page 207: ...C address connected to the IM 1000 User Name The identifid name of record in the computer Computer Name The identified name on the internet in this computer IP Address The IP address on the internet in the computer MAC Address The identified address in the network adapters in the computer The ARP table in Web UI 206 ...

Page 208: ... Select the refresh time period in Manually drop down menu Or click Refresh and system will instantly refresh the connection record information Click the service item to view then system shows all connections of the chosen items Click to search the related connection information Connection record System shows all connection information 207 ...

Page 209: ...Record Info Status Search the related connection information 208 ...

Page 210: ... Log it records events occurred in IM 1000 such as modify settings anomaly flow alert forwarding mails file delete action and etc Click and search the event Click IM 1000 shows the event information in detail Event log Search the events 209 ...

Page 211: ...Event Log Status System shows event log in detail 210 ...

Reviews: