500
Generating reports
Analysis reports
Common Web Sites
These reports provide details of Web access activity detected by the security gateway, letting you
identify whether your Web access policy is performing as desired.
VPN Analysis
These reports detail VPN activity that has occurred during the previous 24-hour period. There is a one-
to-one correspondence between report detail lines and the log messages that were written during the
24-hour period.
IDS/IPS
These reports lists all IDS/IPS events detected by the security gateway over the previous 24 hours. It
displays each event type, action, or interface listed, and the number of the events that have occurred
with the specified time period.
Note:
The Interfaces column will be concatenation of interface and logged and blocked settings. This is
because data structure for reports is a hashmap, and can not have two separate entries for each
interface.
Table 13-2
Common Web Sites report categories
Report view
Description
Top Bytes Transferred by
Source
Lists and details (bytes) the source addresses who have most often accessed the sites
through the security gateway.
Top Bytes Transferred by
Web Site
Lists sites (both inside and outside the security gateway) with the highest amount of
data traffic (bytes), providing bandwidth issue information.
Table 13-3
VPN Analysis report categories
Report view
Description
Clientless VPN Summary
by User
Shows top 10 clientless VPN users and the number of sessions and byes transferred
for each.
Gateway-to-Gateway
Summary Report
Shows top 10 gateway-to-gateway tunnel IDs and the number of sessions for each.
Client VPN Summary
Report
Shows top 10 Client VPN users and the number of session for each.
Detailed Client VPN
Summary Report
Shows the top 20 Client VPN tunnels by source and destination endpoint and the
number of sessions for each.
Table 13-4
IDS/IPS report categories
Report view
Description
IDS/IPS Event Summary
Lists each type of IDS/IPS event, each showing the number of times that type event
has occurred.
IDS/IPS Action Summary
Displays the logged and prevented count and the number of messages with that
value.
IDS/IPS Summary by
Interface
Displays the number of IDS/IPS events received on each interface.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...