
487
Monitoring the security gateway
Alerting using notifications
Prerequisites
None.
To configure a Blacklist notification
1
In the SGMI, in the left pane, under Monitors, click
Notifications
.
2
In the right pane, on the Notifications window, click
New > IDS/IPS Blacklist Notification
.
3
In the ISDS/IPS Blacklist Notification Properties dialog box, on the General Tab, to enable blacklist
notification, check
Enable
.
4
In the Notification Name text box, type a name for the blacklist notification.
5
Optionally, in the Time Period drop-down list, you can select the time period during which blacklist
notifications are sent. For example, you can have notifications sent only during working hours.
6
In the Caption text box, type a brief description of the notification.
7
On the Blacklist tab, do one of the following:
■
To have the Notify daemon send the blacklist information to the local security gateway, click
Local firewall
.
■
To have the Notify daemon send the blacklist information to a remote security gateway, click
Remote firewall
. If you selected this option, do the following:
8
On the Severity tab, to set the severity levels which will trigger the blacklist notification, check the
appropriate severity levels.
9
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
10
Click
OK
.
11
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
12
If you set the security level for triggering a notification to Alert, you can use the Alert Threshold
tab in the Rule Properties dialog box to control when alert events are logged.
Related Information
For further information related to this topic, see the following:
■
“IDS/IPS Blacklist Notification Properties—General tab”
■
“IDS/IPS Blacklist Notification Properties—Blacklist tab”
■
“IDS/IPS Blacklist Notification Properties—Severity tab”
■
“Configuring a time period range”
■
“Configuring a time period group”
■
“Applying alert thresholds to rules”
Firewall
Type the IP address or fully-qualified domain name of the remote security
gateway.
Port
Type the port number over which to send the blacklist information to the remote
security gateway.
Password
Type the administrator password for the remote security gateway.
Confirm Password
To confirm the password, type the password again.
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...