User Guide
99
HostWatch
The HostWatch display uses the logging settings configured for your Firebox using
the Policy Manager. For instance, to see all denied attempts at incoming Telnet in
HostWatch, configure the Firebox to log incoming denied Telnet attempts.
The line connecting the source host and destination host is color-coded to display the
type of connection being made. These colors can be changed. The defaults are:
•
Red
– The connection is being denied.
•
Blue
– The connection is being proxied.
•
Green
– The connection is using network address translation (NAT).
•
Black
– The connection falls into none of the first three categories.
Representative icons appear next to the server entries for HTTP, Telnet, SMTP, and
FTP.
Name resolution might not occur immediately when you first start HostWatch. As
names are resolved, HostWatch replaces IP addresses with host or usernames,
depending on the display settings. Some machines might never resolve, and the IP
addresses remain in the HostWatch window.
To start HostWatch, click the HostWatch icon (shown at left) on the
Control Center
QuickGuide
.
HostWatch display
The upper pane is split into two sides, Inside and Outside. Double-click an item on
either side to produce a pop-up window displaying detailed information about
current connections for the item. The
Connects For
window displays the IP
addresses, port number, connection type, direction, and other detailed information
about these connections.
The lower pane displays detailed information for connections directly related to the
Firebox. Double-click a connection to view details regarding a specific host.
Connecting to a Firebox
From HostWatch:
1
Select
File => Connect
.
You can also click the Firebox icon.
2
Use the
Firebox
drop list to select a Firebox.
You can also type the Firebox name or IP address.
3
Enter the Firebox read-only password. Click
OK
.
HostWatch connects to the Firebox and begins the real-time display.
Replaying a log file
You can replay a log file in HostWatch in order to troubleshoot and retrace a
suspected break-in. From HostWatch:
1
Select
File => Open
.
You can also click the Folder icon. The Open dialog box appears.
Summary of Contents for Firebox FireboxTM System 4.6
Page 1: ...WatchGuard Firebox System User Guide Firebox System 4 6 ...
Page 16: ...6 ...
Page 20: ...LiveSecurity broadcasts 10 ...
Page 44: ...LiveSecurity Event Processor 34 ...
Page 52: ...Defining a Firebox as a DHCP server 42 ...
Page 68: ...Service precedence 58 ...
Page 78: ...Configuring a service for incoming static NAT 68 ...
Page 92: ...Establishing an OOB connection 82 ...
Page 94: ...84 ...
Page 112: ...HostWatch 102 ...
Page 118: ...Working with log files 108 ...
Page 130: ...120 ...
Page 158: ...Configuring debugging options 148 ...