Chapter 12: Setting Up Logging and Notification
200
WatchGuard Firebox System
Logging and notification are crucial to an effective network
security policy. Together, they make it possible to monitor
your network security, identify both attacks and attackers,
and take action to address security threats and challenges.
WatchGuard logging and notification features are both
flexible and powerful. You can configure your firewall to
log and notify a wide variety of events, including specific
events that occur at the level of individual services. For
more information on logging, see the following collection
of FAQs:
https://support.watchguard.com/advancedfaqs/log_main.asp
Developing Logging and Notification Policies
When creating a logging policy, you spell out what gets
logged and when an event or series of events warrants
sending out a notification to the on-duty administrator.
Developing these policies simplifies the setup of individual
services in the WatchGuard Firebox System. If you have
fully mapped out a policy, you can more easily delegate
configuration duties and ensure that individual efforts do
not contradict the overall security stance or logging and
notification policies.
Logging policy
Specifically, the logging policy delineates:
•
Which events to log
•
Which service events to log
•
Which servers are allocated as log hosts
•
How large a log file is allowed to become and how
often a new log file is created
In general, you want to log only the events that might indi-
cate a potential security threat, and ignore events that
would waste bandwidth and server storage space. This
generally translates into logging spoofs, IP options, probes,
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...