12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

256 Log messagesAlert messages (500-599)499 - The scan engine has crashedDescription: The antivirus scan engine has encountered a severe error. It should be restarted automatically. In processscans, it generates additional log messages.Alert messages (500-599)Messages in the range 500-599 indicate that a security rule has been triggered, and could potentially besomeone attempting to breach the network perimeter.501 - Access threshold reachedDescription: One of the suspicious activity thresholds has been reached. Check which rule has been triggered. Althoughthis message may indicate an attack, it is more likely a common service, like HTTP, getting heavy use.501 - RepeatedDescription: Messages that have occurred multiple times have been consolidated, indicating the possibility of anoccurrence of a more serious problem.502 - Ethernet address mismatch (ARP returns )Description: When creating a host entity, you have the option of defining the MAC address along with the IP address.Connecting to the security gateway using this host prompts the security gateway to perform both an ARPand reverse ARP (RARP) to ensure that both the IP address and MAC address returned match theconfiguration. If the MAC address does not match, it could be a misconfiguration, or possibly another hostspoofing the address.502 - Potential denial-of-service (DoS) attack, so blocking IP for at least secondsDescription: The kernel sends this alert.502 - Reverse address does not match, so deniedDescription: The security gateway resolves host names for all connecting IP addresses. As an additional security check,the security gateway performs reverse lookups on host names to ensure that they match their respective IPaddress. If the returned IP address does not match the original, the connection is dropped.505 - Unauthorized process killedDescription: The vulture routine found an unauthorized user service running and killed it. Either ignore, if the servicewas not supposed to be running, or add that service to the vulture.runtime file.506 - Unauthorized user logged offDescription: The vulture daemon has logged off an unauthorized user. Either ignore, if the user account was notsupposed to be running, or add that user name to the vulture.runtime file.507 - Unauthorized user account disabledDescription: (Microsoft Windows only) A user account that was not found registered with the security gateway wasdisabled.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!