494
Monitoring the security gateway
Integrating Symantec DeepSight Threat Management System
Related Information
For further information related to this topic, see the following:
■
“SNMP V2 Trap Notification Properties—General tab”
■
“Configuring a time period range”
■
“Configuring a time period group”
■
“Applying alert thresholds to rules”
Integrating Symantec DeepSight Threat Management System
The Symantec DeepSight Threat Management System is a Symantec product for correlating log files
from many different systems throughout the world and highlighting security threats and trends.
Symantec DeepSight offers visual diagnostics about your firewall states and proactive alerting to guide
you to correct responses to threats.
Symantec DeepSight lets you see the threats experienced by your appliances in relation to the security
threats worldwide, and take preventative measures against these threats. The Alerting Services
provides alerting on particular threats along with recommendations for actions to be taken.
Integrating Symantec DeepSight requires installing two components together on a remote client
computer:
■
DeepSight Extractor
■
Remlog tools
These two components are found on Symantec Gateway Security 5600 Series product OS restore CD-
ROM, in the ClientSoftware directory. The
Symantec™ DeepSight™ Extractor for the Symantec™
Gateway Security 5000 Series v3.0 Installation and Configuration Instructions
,
is found in the SGS 5000
Series v3.0/DeepSight Extractor Documentation folder on the Documentation CD-ROM.
To get Symantec DeepSight analysis, register with the Symantec DeepSight™ Analyzer on the
following Web page:
Prerequisites
Complete the following task before beginning this procedure:
■
“Creating machine accounts for security gateway access from remote computers”
To integrate the Symantec DeepSight Threat Management System
1
On Symantec Gateway Security 5600 Series OS restore CD-ROM, in the ClientSoftware directory,
read the documentation for installing Symantec DeepSight and understand how to install it with
remlog. The directions for how to install it with remlog are found in the file Extractor for SGS 5000
Series v3_0.PDF.
2
Remlog and its instructions for use are also found in the zip files in the RemoteTools directory on
the OS restore CD-ROM.
3
To launch the Symantec DeepSight Extractor, click the DeepSight Extractor installation icon.
4
Once installed, in the SGMI, on the Home page, in the right pane, click the DeepSight link.
5
On the Symantec Security Response Web page for DeepSight, to license and use Symantec
DeepSight, click the link to the Symantec DeepSight Threat Management System.
Related Information
None.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...