18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 20: IPS Attack and System Event Responses<br />

<strong>Sidewinder</strong> <strong>G2</strong> SNMP traps<br />

580<br />

• MAIL_FILTER_FAILURE — This trap is sent when SMTP mail messages<br />

fail a configured mail filter. For example, if a mail message failed the Key<br />

Word Search filter, a mail filter failure event would be logged.<br />

The mail filter map configuration determines what is done with failed messages.<br />

• IPSEC_FAILURE — This trap is sent when IPSec errors exceed the<br />

configured threshold values.<br />

• LICEXCEED_FILTER — This trap is sent when users are denied access<br />

through the <strong>Sidewinder</strong> <strong>G2</strong> due to a user license cap violation.<br />

• LOG_FILE_OVERFLOW — This trap is sent when the <strong>Sidewinder</strong> <strong>G2</strong> audit<br />

logs are close to filling the partition.<br />

• PROBE_ATTEMPT — This trap is sent when network probe attempts are<br />

detected (that is, any time a user attempts to connect or send a message to<br />

a TCP or UDP port that either has no service associated with it or it is<br />

associated with an unsupported service).<br />

To ignore network probe attempts, create an IP Filter deny rule to discard<br />

probes coming from recognized <strong>of</strong>fenders. See “Ignoring network probe<br />

attempts” on page 578 for key values to configure.<br />

• ACCESS_CONTROL — This trap is sent when the number <strong>of</strong> denied<br />

access attempts to services exceeds a specified number. For example, you<br />

may set up your system so that internal users cannot FTP to a certain<br />

Internet address. If a user tried to connect to that address, the attempt<br />

would be logged as a denial.<br />

• UPS_POWER_FAILURE — This trap is sent when a connected<br />

Uninterruptible Power Supply (UPS) has a power failure and the<br />

<strong>Sidewinder</strong> <strong>G2</strong> is running on UPS battery power.<br />

• PROXY_FLOOD — This trap is sent when potential connection attack<br />

attempts are detected. A connection attack is defined as one or more<br />

addresses launching numerous proxy connection attempts to try and flood<br />

the system. When NSS receives more connection attempts than it can<br />

handle for a proxy, that proxy is briefly stopped (to allow the proxy to “catch<br />

up”) and is then restarted, and an audit event is created.<br />

• DENIED_AUTH — This trap is sent when a user attempts to authenticate<br />

and enters invalid data. For example, if a user is required to enter a<br />

password and entered it incorrectly, the denied auth_filter would log the<br />

event.<br />

Note: This type <strong>of</strong> event is not logged when an administrator attempts to switch<br />

to an unauthorized role (srole) or enter incorrect login information.<br />

• UPS_SYSTEM_SHUTDOWN — This trap is sent when the <strong>Sidewinder</strong> <strong>G2</strong><br />

has been running on UPS battery power for the estimated battery time.<br />

(See “Configuring the <strong>Sidewinder</strong> <strong>G2</strong> to use a UPS” on page 93 for<br />

additional information on UPS.)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!