18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 19: Auditing and Reporting<br />

Generating reports using the Admin Console<br />

554<br />

Report type Description<br />

http_virus This report provides information on Web viruses that are detected by the <strong>Sidewinder</strong><br />

<strong>G2</strong>. The report includes virus frequency, hits by source address, and detected Web<br />

viruses.<br />

ipf_dest_traffic This report lists IP Filter information on the destination host traffic that the <strong>Sidewinder</strong><br />

<strong>G2</strong> connected to, sorted by the number <strong>of</strong> bytes transferred. The report lists the<br />

destination host, the service used, the number <strong>of</strong> kB transferred, and the number <strong>of</strong><br />

connections that were made.<br />

ipf_host_traffic This report produces IP Filter information for source host traffic on internal and external<br />

networks. You might use this data for tracking which systems have the heaviest traffic<br />

going to and from the <strong>Sidewinder</strong> <strong>G2</strong>. The report lists the source host, the number <strong>of</strong> kB<br />

sent to the server, the number <strong>of</strong> kB sent to the client, the total number <strong>of</strong> kB, and the<br />

number <strong>of</strong> connections that were made.<br />

ipf_port_traffic This report lists IP Filter traffic port information that occurred over a specific period <strong>of</strong><br />

time.<br />

The report lists each service, the number <strong>of</strong> kB sent to the server, the number <strong>of</strong> kB sent<br />

to the client, the total number <strong>of</strong> kB, and the number <strong>of</strong> connections that were made.<br />

When a service uses a non-standard port (for example, 8000 or 8010), the service’s<br />

port number will also appear in the Service column.<br />

ipf_traffic This report provides a summary <strong>of</strong> the IP Filter port, host, and destination reports.<br />

mail_virus This report provides information on mail viruses that are detected by the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

The report includes virus frequency, hits by source, and detected mail viruses.<br />

performance This report summarizes utilization information (based on one-hour increments) for CPU<br />

percentage and load average, as well as real, virtual, and mbuf memory usage.<br />

probes_attempted This report lists information about attempts made to connect or send a message to a<br />

<strong>Sidewinder</strong> <strong>G2</strong> port that either has no service associated with it or is associated with an<br />

unsupported service. This report contains a section for probes received in each burb on<br />

the system. The report lists where the probe originated from and how many probes<br />

occurred. The output <strong>of</strong> this report will be similar to the following:<br />

For each burb, the above report lists the time <strong>of</strong> the report,<br />

the interval covered by the report, the source host,<br />

destination host, destination port, and the number <strong>of</strong> probes<br />

generated by this source/destination host pair. Up to five<br />

destination port values are displayed.<br />

Depending on how you have set up your auditing configuration, you may have already<br />

been notified <strong>of</strong> these probe attempts. If you were not notified, you may want to change<br />

your auditing options as described in Chapter 16.<br />

Note: This report is automatically generated and e-mailed on a daily basis to the<br />

<strong>Sidewinder</strong> <strong>G2</strong> administrator. See “Viewing administrator mail messages on <strong>Sidewinder</strong><br />

<strong>G2</strong>” on page 350 for information on viewing this e-mail.<br />

More...

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!