18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Checking system<br />

status<br />

Checking system status<br />

An example <strong>of</strong> how to make additions to the ignore list follows:<br />

If you want to ignore SNMP packets (probe attempts) from an internal<br />

machine, called master.foo.com, destined for a host called slave.bar.com,<br />

do the following:<br />

1. Check the /etc/services file for the name <strong>of</strong> the service you want to<br />

ignore. You can use the port number, the name <strong>of</strong> an existing service for<br />

the port number you want your network to ignore, or you can add an<br />

entry /etc/services.<br />

Note: The name must exist in /etc/services.<br />

2. Using a text editor, add the appropriate line to /etc/sidewinder/<br />

auditbotd.conf.<br />

For the above example you would use the following line:<br />

ignore(0 udp master.foo.com * slave.bar.com snmp)<br />

3. Save the file, and quit the text editor.<br />

The change will take effect the next time auditbotd reads the<br />

configuration file, which is done each time you reload or restart<br />

auditbot. This is done by entering one <strong>of</strong> the following commands:<br />

cf server reload auditbotd<br />

OR<br />

cf server restart auditbotd<br />

In addition to configuring alarm events and strikeback options, you<br />

can display information on the current status <strong>of</strong> your network<br />

connections and take a look at what is happening on the system.<br />

CPU usage<br />

CPU Usage allows you to obtain information on system performance.<br />

To view CPU usage information, enter the following commands at<br />

<strong>Sidewinder</strong> <strong>G2</strong> command prompt:<br />

/usr/sbin/vmstat<br />

/usr/bin/uptime<br />

/usr/contrib/bin/top<br />

Alarm Events and Responses 17-19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!