162 Detecting
Configuring sensor detection
See
“Restarting sensors via the Network Security console”
on page 49.
Note:
SuperUsers and Administrators can restart sensors at any time;
StandardUsers, and RestrictedUsers cannot. See
“User groups reference”
on
page 319 for more about permissions.
Basic sensor parameters
We recommend that you tune all of the basic parameters to the normal traffic
patterns of your network. At installation, leave the sensor parameters at default.
Observe how the system detects events. Then adjust these parameters as needed
until they are just barely alerting, such as once a day, under normal conditions
for your environment.
In this way, you will quickly notice a shift in traffic patterns and easily pinpoint
the events that triggered the alert.
This section describes the following sensor detection parameters:
■
Enable Flow Statistics Collection
■
Enable Full Packet Capture
■
TCP Flood Alert Threshold
■
UDP Flood Alert Threshold
■
Slow Scan Alert Threshold
■
ICMP Saturation Alert Threshold
Modifying some sensor
configuration parameters
You must restart the sensor for the action
to take effect.
Applying protection policies
Starts the sensor automatically.
Unapplying protection policies
Stops the sensor automatically.
Removing interface groups
Stops the sensor automatically.
Modifying interface groups
Restarts the sensor automatically.
Applying engine updates
Restarts the sensor automatically.
Restoring configuration from
backup
Restarts the sensor automatically.
Table 7-1
Restarting sensors
Action
Response
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...