644
Field descriptions
Policy field descriptions
IDS Event Type Properties dialog box—Description tab
Optionally, provides an extended description. This information is useful to help track changes or it can
be used as criteria for searches.
The maximum length is 20,000 alphanumeric characters.
IDS/IPS—Portmap tab
On the Portmap tab, you can enable IDS/IPS services and associate protocols with these services so
that intrusion events can be triggered. Pre-defined IDS/IPS services are delivered with the security
gateway. You can remove or reapply pre-defined services, but you cannot add new services.
The Portmap tab contains a list of IDS/IPS services and protocols.
Severity
Displays the severity level of this event.
Severity ratings describe the severity of the threat that the event type covers.
The severity ratings are:
■
Informational
An informational severity level indicates an issue that is not generally considered
malicious, such as policy violations. This rating can also be used for event types that
detect authorized activity or provide troubleshooting information.
■
Low
A low severity level indicates reconnaissance tools, general malicious indicators, and
threats with a low impact.
■
Medium
A medium severity level indicates a threat that poses a medium risk, such as malicious
code execution as a normal user, moderate impact denial-of-service attacks, and
threats permitting write access to important data or read access to sensitive data.
■
High
A high severity level indicates a threat that poses a high risk, such as malicious code
execution as a privileged user, high impact denial-of-service attacks, and widespread
worms of moderate impact.
■
Critical
A critical severity level indicates a threat that poses a high risk, such as a Category 3 or
4 worm.
This field is read-only.
False positive
reliability
States the level of reliability regarding false positives. The scale for false positive reliability
is 1 to 10, with 1 indicating the least reliable and 10 indicating the most reliable.
This field is read-only.
Event code
Displays the event code for the selected event.
This field is read-only.
Log event type
Displays the type of log event for the selected event.
This field is read-only.
Table D-84
IDS Event Type Properties dialog box—General tab (Continued)
Field
Description
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...