Chapter
12
Monitoring the security gateway
This chapter includes the following topics:
■
■
■
■
■
■
■
Integrating Symantec DeepSight Threat Management System
■
Reducing the volume of log messages
About monitoring
The security gateway provides monitoring features that let you see the current status of the appliance,
and take appropriate actions to respond to events in a timely manner. The Monitors section of the
Security Gateway Management Interface (SGMI) has the following sections:
Overall Health
Shows information about the system, including network throughput, system usage, active
connections, and current appliance hardware operating status.
Monitoring your security gateway health makes you aware of pending issues that should be
addressed before they result in major problems. For example, a sudden spike in incoming
traffic through an interface can be the first warning of an attack. Temperature, fan, and disk
warnings can alert you to problems with the security gateway appliance.
Status
Shows general and detailed information about the properties of the connections to the security
gateway.
You can see the connection activity on the security gateway since it was last started and details
about the connections that are currently active.
If you configure client compliance for remote users, you can see the update status of the
servers that are providing antivirus protection.
If you have enabled hardware encryption, you can run diagnostics.
For clientless VPN users, you can view and unlock accounts that have been locked as a result of
failed logon attempts.
Logs
Lets you view and filter information about system events.
For example, when you see unusual activity in the Overall Health window, you can view the
security logs to identify the source of the activity and determine whether a problem exists.
If you have implemented intrusion detection and prevention (IDS/IPS) on your interfaces,
filters, or clientless VPN connection methods, the IDS/IPS alerts tab lets you view the log
messages that are generated by IDS/IPS events.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...