Integrating Intrusion Detection
User Guide
193
and monitor sites that attempt access to restricted ports on
your network.
Configuring a service to temporarily block
sites
Configure the service to automatically block sites that
attempt to connect using a denied service. From Policy
Manager:
1
Double-click the service icon in the Services Arena.
The Properties dialog box appears.
2
Use the
Incoming
service
Connections Are
drop list to
select
Enabled and Denied
.
3
Select the checkbox marked
Auto-block sites that
attempt to connect via
service
, located at the bottom of
the dialog box.
Viewing the Blocked Sites list
The Blocked Sites list is a compilation of all sites
currently blocked by the Firebox. Use Firebox
Monitors to view sites that are automatically
blocked according to a service’s property configuration.
From System Manager, click the
Blocked Site List
tab at
the bottom of the graph. (You might need to use the arrows
to access this tab.)
Integrating Intrusion Detection
Intrusion detection is an important component of a
defense-in-depth security policy. A good intrusion detec-
tion system (IDS) examines over time the source, destina-
tion, and type of traffic directed at your network and
compares it against known patterns of attack. When a
match occurs, it tells you the nature of the attack and rec-
ommends possible courses of action.
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...