User Guide
199
CHAPTER 12
Setting Up Logging
and Notification
An
event
is any single activity that occurs at the Fire-
box, such as denying a packet from passing through
the Firebox.
Logging
is the recording of these events to
a log host. A
notification
is a message sent to the
administrator by the Firebox when an event occurs
that indicates a security threat. Notification can be in
the form of email, a popup window on the Watch-
Guard Security Event Processor (WSEP), a call to a
pager, or the execution of a custom program.
For example, WatchGuard recommends that you con-
figure default packet handling to issue a notification
when the Firebox detects a port space probe. When the
Firebox detects one, the log host sends notification to
the network security administrator about the rejected
packets. At this point, the network security adminis-
trator can examine the logs and decide what to do to
further secure the organization’s network. Some possi-
ble courses of action would be to:
•
Block the ports on which the probe was attempted
•
Block the IP address that is sending the packets
•
Contact the ISP through which the packets are
being sent
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...