12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

104 Monitoring security gateway trafficSESA event gatingMessages logged to SESA may not always appear identical to what is seen in the local log file. The majorityof log messages sent to SESA appear very similar to their local counterparts, but there is some minorvariations from time to time.Note: If you join a security gateway to SESA, the default configuration sends only a small subset of eventsto SESA. Turning on all events incurs additional overhead, and may slow system performance. Carefullyconsider your selections when determining the events to send to SESA.The major SESA classes and subclasses that log messages are assigned are listed in Table 8-1.Table 8-1Class or subclassStatistics<strong>Security</strong> GatewaySESA event classes and subclassesDescriptionProvides statistical information about each connection.Provides for possible attack, process killed, and remote management connection events.Authentication FailuresNetworkConfigurationAuthenticationIDS/IPSDuplicateManagementReconfigurationAntivirusGeneralConnectionRuleStateVersionComponentViolationCoreLicenseAny log message indicating that a user has been denied access to a service due to anauthentication failure.Logs detailed network errors between two endpoints of communication, a range ofaddresses for filtering, or a specific network client request.Reports configuration information about a network driver or network service.Reports network events at the driver level normally generated by the filter driver or VPNservices.Intrusion events found by the intrusion detection and prevention component.Notifies SESA that the local logging service (logserviced) has consolidated messages.Logs detailed information on entity management, configuration issues, and systemreconfiguration.Reports to a global administrator when a severe configuration problem has been found, anda reconfiguration of the component is necessary. These messages are normally about theDNS configuration or configuration files.Viruses found by the antivirus scan engine. The proxies may also log a virus foundmessage.Provides general logging of information. This class would be used when log messages donot fall into any other class or subclass.Lower-level, connection-oriented messages.Reports any action that was denied by an explicit rule, or implicit rule (those that violatesecurity gateway acceptable behavior).Reports state change information about a component or hardware feature of the securitygateway. Included in this subclass are start and stop messages, as well as hardware CPUtemperature.Reports the version number of the security gateway and its components.Includes errors related to process interaction.Reports component interactions that violate policies.Reports errors occurring within components that result from fundamental system orcommunication errors.Includes errors related to licensing.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!