12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Monitoring security gateway trafficAdvanced options111Table 8-3ParameterAdvanced options (Continued)Descriptionmisc.httpd.mimeblacklistmisc.httpd.urlblacklistmisc.logServiced.logsesaooba.mime_types.addooba.mime_types.removeOption to modify the default behavior of the blocked MIME types forHTTP traffic. By default, this option is set to True and any MIME typeslisted are blocked. Anything not listed is allowed. IF this option ischanged to False, all MIME types listed are now allowed, and all othersare blocked.Option to modify the default behavior of the URL list for HTTP traffic.By default, this option is set to False and any URLs added to the listdesignate allowed sites. All others are blocked. IF this option is changedto True, all URLs added to the list are now blocked, and all others areallowed.Determines whether or not logging to SESA takes place. The default isfalse. You must join SESA to begin sending messages. This flag does nothave an affect until you send log messages to SESA.Defines new MIME types to be added to the OOBA server.Defines new MIME types to be removed from the OOBA server.portcontrol.enable_tcp_ports TCP ports to enable. The default is 2456.Note: 2456 is the default used by the <strong>Security</strong> Gateway ManagementInterface when managing the security gateway. Unless the default haschanged, this variable should always include 2456. If the default porthas changed, this parameter should always have that new valuedefined. If not, you can no longer manage the security gateway from aremote Web browser.portcontrol.enable_udp_portstacacs.auth_keytacacs.auth_methodtacacs.server_ipui.inactivity_timeoutUDP ports to enable.Secret key used for authentication with the TACACS+ server.Method for authentication with the TACACS+ server.TACACS+ server IP address. Acceptable arguments include any valid IPaddress.Period of time in minutes of inactivity before re-authentication isrequired. The default is 15 minutes.ui.status_poll_interval Period of time in seconds between system status calls. The default is 30seconds.vultured.elapsetimevultured.usersTime in seconds between vulture scans. The default is 60 seconds.Setting this value to -1 disables the vulture process.System users permitted to run processes and services. The default isroot, daemon, and bin for the Symantec Gateway <strong>Security</strong> 5400 Seriesand Administrator for the Symantec Enterprise Firewall.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!