18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring alarm events and event responses<br />

17-4 Alarm Events and Responses<br />

Table 17-2. Pre-defined filter descriptions<br />

Filter Name Description<br />

attack_filter Detects attack attempts (that is, any suspicious<br />

occurrence) identified by one <strong>of</strong> the services on the<br />

<strong>Sidewinder</strong> <strong>G2</strong>. For example, if the Network Services<br />

Sentry (NSS) detects a suspicious IP address on an<br />

incoming connection, it will issue an attack attempt.<br />

deniedauth_filter Detects when a user attempts to authenticate and<br />

enters invalid data. For example, if a user is required to<br />

enter a password and entered it incorrectly, the denied<br />

auth_filter would log the event. (Note that this type <strong>of</strong><br />

event is not logged when users attempt to switch to an<br />

unauthorized role or enter incorrect login information.)<br />

failover_filter Detects any time a <strong>Sidewinder</strong> <strong>G2</strong> changes its status in<br />

an HA cluster from secondary to primary, or from<br />

primary to secondary.<br />

filterfail_filter Detects SMTP mail messages that fail a configured mail<br />

filter. For example, if a mail message failed the Key Word<br />

Search filter, a mail filter failure event would be logged.<br />

hardware_s<strong>of</strong>tware_fail Detects failure <strong>of</strong> a critical component. For example, this<br />

trap occurs when daemond detects a s<strong>of</strong>tware module<br />

has failed.<br />

ipsec_filter Detects IPSec errors that exceed the configured<br />

threshold values.<br />

licexceed_filter Detects when the <strong>Sidewinder</strong> <strong>G2</strong> has begun denying<br />

users access due to a user license cap violation.<br />

logoverflow_filter Detects when the <strong>Sidewinder</strong> <strong>G2</strong> audit logs are close to<br />

filling the partition.<br />

netprobe_filter Detects network probe attempts (that is, any time a user<br />

attempts to connect or send a message to a TCP or UDP<br />

port that either has no service associated with it or it is<br />

associated with an unsupported service). See “Ignoring<br />

network probe attempts” on page 17-17 for more<br />

information.<br />

networkacl_filter Detects when the number <strong>of</strong> denied access attempts to<br />

services exceeds a specified number. For example, you<br />

may set up your system so that internal users cannot<br />

FTP to a certain Internet address. If a user tried to<br />

connect to that address, the attempt would be logged<br />

as a denial.<br />

More . . .

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!