151
Responding
Setting response actions
reached before the maximum time, then traffic record stops recording, but waits
until the maximum time has expired before starting a new record action. The
number of responses per incident is also determined by the response
configuration. The minimum delay between responses is 1 minute.
Note:
This response action records only fully assembled packets from actual
flows, not malformed packets or packet fragments. You can view detected
packet contents in the Advanced tab of Event Details.
See
“Viewing event details”
on page 197.
Caution:
Traffic record files are stored in the
/usr/SNS/record
directory, and
can quickly fill the disk space, especially on a gigabit link. Make sure that this
directory contains sufficient disk space.
To enable traffic records
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
In
Response Rules
, click the
Response Action
column of a rule.
3
In
Configure Response Action
, click
Traffic Record
.
4
Provide the following information:
■
Maximum packets to record
: Enter the maximum number of packets
per incident of this response.
■
Maximum # of record actions
: Enter the maximum number of records
per incident of this response.
■
Maximum time to record (mins)
: Enter the time in minutes that you
want Symantec Network Security to record per incident.
5
Click traffic record match parameters to select them:
■
Source IP
: Click this parameter if you want to record only traffic with
the same source address as the triggering event.
■
Source Port
: Click this parameter if you want to record only traffic with
the same source port as the triggering event.
■
Destination IP
: Click this parameter if you want to record only traffic
with the same destination address as the triggering event.
■
Destination Port
: Click this parameter if you want to record only
traffic with the same destination port as the triggering event.
■
Transport
: Click this parameter if you want to record only traffic with
the same transport protocol (such as TCP, UDP or ICMP) as the
triggering event.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...