Chapter 11: Intrusion Detection and Prevention
192
WatchGuard Firebox System
Auto-blocking sites that try to use blocked
ports
You can configure the Firebox such that when an outside
host attempts to access a blocked port, that host is tempo-
rarily auto-blocked.
In the
Blocked Ports
dialog box, select the checkbox
marked
Auto-block sites that attempt to use blocked
ports
.
You can also auto-block sites using protocol anomaly
detection. For more information, see “Configuring the
Incoming SMTP Proxy” on page 138.
Setting logging and notification for blocked
ports
You can also adjust your event logs and notification to
accommodate attempts to access blocked ports. You can
configure the Firebox to log all attempts to use blocked
ports, or notify a network administrator when someone
attempts to access a blocked port.
From the
Blocked Ports
dialog box:
1
Click
Logging
.
The Logging and Notification dialog box appears.
2
In the
Category
list, click
Blocked Ports
.
3
Modify the logging and notification parameters
according to your security policy preferences.
For detailed instructions, see “Customizing Logging and
Notification by Service or Option” on page 215.
Blocking Sites Temporarily with Service
Settings
Use service properties to automatically and temporarily
block sites when incoming traffic attempts to use a denied
service. You can use this feature to individually log, block,
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...