18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Generating and<br />

viewing reports<br />

using the Admin<br />

Console<br />

Generating and viewing reports using the Admin Console<br />

You might choose to do this if you want one file to contain all logging<br />

information or if you want to send audit data to another host system<br />

on your network.<br />

Viewing syslog messages<br />

To view syslog messages, display the following files.<br />

/var/log/messages<br />

/var/log/daemon.log<br />

The following illustrates sample Logfile Messages.<br />

Mar 25 14:05:41 MyFirewall kernel: ef0: interfaces:<br />

AUI, 10Base2<br />

Mar 25 14:05:41 MyFirewall kernel: ef0: rxf=5119<br />

txf=3068<br />

Mar 25 14:05:41 MyFirewall kernel: ef1 at isa0 iobase<br />

0x300<br />

Mar 25 14:05:41 MyFirewall kernel: ef1: 3C509-COMBO,<br />

Important: If you receive a message “Response from unexpected source” it usually<br />

indicates name service responses sent by multihomed servers. Some multihomed servers<br />

select the wrong source IP address when sending the response. When the <strong>Sidewinder</strong> <strong>G2</strong><br />

receives the response, it ignores it and logs a message in /var/log/messages. The example<br />

below displays what you would see in the syslog when this happens.<br />

Aug 31 12:57:56 shore named (1) [85]: Response<br />

from unexpected source ([192.55.214.1].53)<br />

Aug 31 12:57:57 shore named (1) [85]: Response<br />

from unexpected source ([199.199.125.108].53)<br />

Aug 31 13:03:51 shore named (1) [85]: Response<br />

from unexpected source ([204.52.248.130].53)<br />

The <strong>Sidewinder</strong> <strong>G2</strong> Reports window in the Admin Console allows you<br />

to generate commonly used reports based on pre-defined report<br />

formats, such as administrative user connections, network probe<br />

attempts, traffic information, and active rule (ACL) usage to name a<br />

few.<br />

Monitoring, Auditing, and Reporting 18-23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!