130 Responding
About response rules
functionality that is unique to an appliance. Each section describes this
additional functionality in detail.
Symantec Network Security can take the following types of actions to respond to
attacks, individually or in sequence:
■
Predefined actions
See
“Setting response actions”
on page 141.
■
Configured custom response actions
See
“Setting a custom response action”
on page 147.
■
Triggered actions from third-party applications via Smart Agents
See
“Integrating third-party events”
on page 282.
■
No actions
See
“Setting no response action”
on page 142.
■
Responding at the point of entry
See
“Defining new protection policies”
on page 120.
The following diagram provides an overview of response policy procedures:
1. Add new rule
2. Choose action to set
3. Set parameters
Set target
Set type
Set severity
Set action
Set source
Set next action
Take no action
Export flow data
Notify via console
Notify via email
Notify via SNMP
Record traffic
Reset TCP
Take customized action
Track suspicious event
SNMP Manager
From Address
Subject Line
SMTP Server
Hostname for Email
Notifications
SNMP Community String
and confidence
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...