
195
Chapter 20
20.
Logging and Reporting
Logging is an important part of a properly configured firewall. Administrators can use
the information in logs to gather usage statistics, monitor activities, check for problems,
and investigate potential attacks. The logging features of the Gauntlet Internet Firewall
provide administrators with a wealth of information about activities to and through the
firewall. The logging features present the information in several formats. You should, of
course, configure both the logging and reporting features to match your security policy.
This chapter describes the concepts behind logging and reporting systems, configuring
these systems, and understanding the log and report formats.
Understanding Logging and Reporting
The Gauntlet Firewall follows the philosophy that it is easy to compress, consolidate,
summarize, and delete log information; it is impossible to retroactively gather log
information on an event that has already occurred. Disk space is a lot cheaper than
spending many hours debugging a problem that a program would have written to the
logs. For these reasons, the components of the Gauntlet Firewall log a wide variety of
activities and attributes.
These are the components of the Gauntlet Firewall:
•
firewall kernel
•
proxies
•
authentication management system
•
DNS
•
sendmail
Summary of Contents for Gauntlet
Page 1: ...Gauntlet for IRIX Administrator s Guide Document Number 007 2826 004 ...
Page 16: ......
Page 26: ......
Page 27: ...PART ONE Understanding the Gauntlet Internet Firewall I ...
Page 28: ......
Page 43: ...PART TWO Configuring and Using Proxies II ...
Page 44: ......
Page 50: ......
Page 56: ......
Page 64: ......
Page 72: ......
Page 94: ......
Page 109: ...PART THREE Administering General Gauntlet Firewall Services III ...
Page 110: ......
Page 140: ......
Page 147: ...Introductory Management Form 121 Figure 17 4 Gauntlet Introductory Management Form 2 of 3 ...
Page 155: ...Routing Configuration Form 129 Figure 17 8 Routing Configuration Form ...
Page 163: ...Proxy Servers Configuration Form 137 Figure 17 11 Proxy Servers Configuration Form 2 of 3 ...
Page 170: ...144 Chapter 17 The Graphical Management Interface Figure 17 13 DNS Configuration Form 1 of 2 ...
Page 171: ...DNS Configuration Form 145 Figure 17 14 DNS Configuration Form 2 of 2 ...
Page 177: ...Sendmail on Gauntlet Servers 151 Figure 17 15 Sendmail Configuration Form ...
Page 187: ...Logfiles and Reports Configuration Form 161 Figure 17 20 Reports and Logfiles Form 1 of 2 ...
Page 191: ...Authorizing Users Form 165 Figure 17 22 Authorizing Users Form ...
Page 192: ...166 Chapter 17 The Graphical Management Interface Figure 17 23 Add User Form ...
Page 214: ......
Page 232: ......
Page 233: ...Appendixes IV ...
Page 234: ......
Page 294: ......
Page 305: ......