18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Generating and viewing reports using the Admin Console<br />

Report Type Description<br />

probes_attempted This report lists information about attempts made to connect or send a message to a<br />

<strong>Sidewinder</strong> <strong>G2</strong> port that either has no service associated with it or is associated with an<br />

unsupported service. This report contains a section for probes received in each burb on the<br />

system. The report lists where the probe originated from and how many probes occurred. The<br />

output <strong>of</strong> this report will be similar to the following:<br />

For each burb, the above report lists the time <strong>of</strong> the report, the interval covered by the report,<br />

the source host, destination host, destination port, and the number <strong>of</strong> probes generated by<br />

this source/destination host pair. Up to five destination port values are displayed.<br />

Depending on how you have set up your auditing configuration, you may have already been<br />

notified <strong>of</strong> these probe attempts. If you were not notified, you may want to change your<br />

auditing options as described in Chapter 16.<br />

Note: This report is automatically generated and e-mailed on a daily basis to the <strong>Sidewinder</strong> <strong>G2</strong><br />

administrator. See “Viewing administrator mail messages on <strong>Sidewinder</strong> <strong>G2</strong>” on page 11-6 for<br />

information on viewing this e-mail.<br />

root_accesses This report contains a list <strong>of</strong> root access attempts by users who used the srole command to<br />

change roles. This report lists the date that the root access attempts occurred, the service<br />

(srole), the result <strong>of</strong> the attempt, which domain the user tried to srole to, and who the<br />

user was. This report is generated daily.<br />

service_denied This report lists instances when users were denied access to a service because <strong>of</strong> the<br />

restrictions you set up in your active rules (also referred to as the Access Control List, or ACL).<br />

The report lists the source and destination hosts, the user, the service that was denied, and the<br />

total number <strong>of</strong> times a check was made. The meaning <strong>of</strong> these events depends on several<br />

factors, including your site’s security policies. The report could indicate that an internal user is<br />

trying to access an unauthorized system on the Internet. It might also indicate a service that<br />

internal users need, and you may want to consider making it available.<br />

Note: This report is automatically generated and e-mailed on a daily basis to the <strong>Sidewinder</strong> <strong>G2</strong><br />

administrator. See “Viewing administrator mail messages on <strong>Sidewinder</strong> <strong>G2</strong>” on page 11-6 for<br />

information on viewing this e-mail.<br />

service_traffic This report lists proxy information on how <strong>of</strong>ten Internet services were used during a specific<br />

period <strong>of</strong> time. You can use this information to gauge how heavily your <strong>Sidewinder</strong> <strong>G2</strong> is being<br />

used.<br />

The report lists each service, the number <strong>of</strong> kB sent to the server, the number <strong>of</strong> kB sent to the<br />

client, the total number <strong>of</strong> kB, and the number <strong>of</strong> connections that were made. When a service<br />

uses a non-standard port (for example, 8000 or 8010), the service’s port number will also<br />

appear in the Service column.<br />

Note: This report is automatically generated and e-mailed on a daily basis to the <strong>Sidewinder</strong> <strong>G2</strong><br />

administrator. See “Viewing administrator mail messages on <strong>Sidewinder</strong> <strong>G2</strong>” on page 11-6 for<br />

information on viewing this e-mail.<br />

18-28 Monitoring, Auditing, and Reporting<br />

More . . .

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!