486
Monitoring the security gateway
Alerting using notifications
5
To display alerts that contain specific parameters, do the following:
■
Click
Parameters
, and then click
Add
.
■
In the Select Parameters dialog box, in the Log Parameter Name list, select a parameter that
should appear in the displayed alerts, and then click
OK
.
You can use the Search capability to make it easier to find a parameter.
■
In the Set Parameter Value dialog box, in the text box, type the parameter value to be
associated with the selected parameter, and then click
OK
.
6
To display alerts that occur on specific security gateways, do the following:
■
Click
System Names
.
■
In the Value text box, type the security gateway name, and then click
Add
.
7
To display alerts with specific process IDs, do the following:
■
Click
Process IDs
.
■
In the Value text box, type the process ID, and then click
Add
.
8
To display alerts with specific message numbers, do the following:
■
Click
Message Numbers
.
■
In the Value text box, type the message number, and then click
Add
.
9
To display alerts whose message text includes specific text patterns, do the following:
■
Click
Text Patterns
.
■
In the Value text box, type the text pattern, and then click
Add
.
10
Click
OK
.
Related Information
For further information related to this topic, see the following:
■
“Performing a basic IDS/IPS alert search”
■
“Performing an advanced IDS/IPS alert search”
Alerting using notifications
Notifications free up valuable time, letting you focus on other responsibilities while ensuring that
security gateway issues do not go unnoticed. Notifications are configured to alert administrators by
email, pager, or SNMP message when events requiring attention occur. You can also configure the
security gateway to invoke an application, potentially resolving an issue without administrator
intervention.
Each notification method that the security gateway generates is built from a common template. All
notifications consists of one or more message severity levels and a time frame to watch. The
differences for these methods lie in the action taken and when the security gateway should invoke the
notification.
Configuring IDS/IPS blacklist notifications
You can configure the security gateway to drop all packets from a source address for a set period of
time. The default is 24 hours. To change the duration, use the advanced option
blacklistd.blacklist_time.
Packets are dropped from a host sending traffic that has been matched against IDS/IPS signatures.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...