Chapter 11: Intrusion Detection and Prevention
188
WatchGuard Firebox System
Logging and notification for blocked sites
From the
Blocked Sites
dialog box:
1
Click
Logging
.
The Logging and Notification dialog box appears.
2
In the
Category
list, click
Blocked Sites
.
3
Modify the logging and notification parameters
according to your security policy preferences.
For detailed instructions, see “Customizing Logging and
Notification by Service or Option” on page 215.
Blocking Ports
You can block ports to explicitly disable external network
services from accessing ports that are vulnerable as entry
points to your network. A blocked port setting takes prece-
dence over any of the individual service configuration set-
tings.
Like the Blocked Sites feature, the Blocked Ports feature
blocks only packets that enter your network through the
external interface. Connections between the optional and
Trusted interfaces are not subject to the Blocked Ports list.
You should consider blocking ports for several reasons:
•
Blocked ports provide an independent check for
protecting your most sensitive services, even when
another part of the firewall is not configured correctly.
•
Probes made against particularly sensitive services can
be logged independently.
•
Some TCP/IP services that use port numbers above
1024 are vulnerable to attack if the attacker originates
the connection from an allowed well-known service
with a port number below 1024. These connections can
be attacked by appearing to be an allowed connection
in the opposite direction. You can prevent this type of
attack by blocking the port numbers of services whose
port numbers are under 1024.
Содержание Firebox X10E
Страница 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Страница 12: ...xii WatchGuard Firebox System ...
Страница 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Страница 61: ...Cabling the Firebox User Guide 39 ...
Страница 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Страница 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Страница 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Страница 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Страница 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Страница 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Страница 255: ...Working with Log Files User Guide 233 appear until the remote office Firebox has been properly configured ...
Страница 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Страница 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...