18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 20: IPS Attack and System Event Responses<br />

Creating system responses<br />

574<br />

Table 40: Description <strong>of</strong> pre-defined system events<br />

Event Description<br />

Access Control List Detects all ACL audit events.<br />

all audit Detects all attack and system events, regardless <strong>of</strong><br />

characteristics.<br />

config change Detects when the <strong>Sidewinder</strong> <strong>G2</strong>’s configuration changes.<br />

error Detects all system events identified as AUDIT_T_ERROR<br />

in the audit stream.<br />

HA failover Detects when a failover IP address changes because a<br />

High Availability cluster failed over to its secondary/<br />

standby.<br />

hardware s<strong>of</strong>tware<br />

failure<br />

host license<br />

exceeded<br />

Detects when a hardware or s<strong>of</strong>tware component fails.<br />

Detects when the number <strong>of</strong> hosts protected by the<br />

<strong>Sidewinder</strong> <strong>G2</strong> exceeds the number <strong>of</strong> licensed hosts.<br />

IPSEC error Detects when traffic generates IPSEC errors.<br />

license expiration Detects when a licensed feature is about to expire.<br />

log overflow Detects when the log partition is close to filling up.<br />

network traffic Detects all connections that successfully pass through the<br />

<strong>Sidewinder</strong> <strong>G2</strong>.<br />

not config change Detects all attack and system events that are not<br />

configuration changes.<br />

power failure Detects when an Uninterruptible Power Supply (UPS)<br />

device detects a power failure and the <strong>Sidewinder</strong> <strong>G2</strong> is<br />

running on UPS battery power.<br />

syslog Detects all audit attacks and system events created via<br />

syslog.<br />

system all Detects all system events <strong>of</strong> all severities, including power<br />

failures, hardware and s<strong>of</strong>tware failures, failover events,<br />

license expiration, host license exceeded, log overflows,<br />

and IPSEC errors.<br />

system critical Detects all critical system events, including power failures,<br />

hardware failures, critical s<strong>of</strong>tware failures, and failover<br />

events. Critical system events indicate that a component<br />

or subsystem stopped working, that the system is going<br />

down (expectedly or unexpectedly), or that the system is<br />

not expected to work again without intervention.<br />

More...

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!