04.03.2013 Views

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using the <strong>OfficeScan</strong> Firewall<br />

To configure the firewall violation outbreak criteria and notifications:<br />

PATH: NOTIFICATIONS > ADMINISTRATOR NOTIFICATIONS > OUTBREAK NOTIFICATIONS<br />

1. In the Criteria tab:<br />

a. Go to the Firewall Violations section.<br />

b. Select Monitor firewall violations on networked computers.<br />

c. Specify the number of IDS logs, firewall logs, and network virus logs.<br />

d. Specify the detection period.<br />

Tip: <strong>Trend</strong> Micro recommends accepting the default values in this screen.<br />

<strong>OfficeScan</strong> sends a notification message when the number of logs is exceeded. For<br />

example, if you specify 100 IDS logs, 100 firewall logs, 100 network virus logs, and<br />

a time period of 3 hours, <strong>OfficeScan</strong> sends the notification when the server receives<br />

301 logs within a 3-hour period.<br />

2. In the Email tab:<br />

a. Go to the Firewall Violation Outbreaks section.<br />

b. Select Enable notification via email.<br />

c. Specify the email recipients.<br />

d. Accept or modify the default email subject and message. You can use token<br />

variables to represent data in the Subject and Message fields.<br />

3. Click Save.<br />

TABLE 11-4. Token Variables for Firewall Violation Outbreak<br />

Notifications<br />

VARIABLE DESCRIPTION<br />

%A Log type exceeded<br />

%C Number of firewall violation logs<br />

%T Time period when firewall violation logs accumulated<br />

11-29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!