11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Integrating Intrusion Detectionand monitor sites that attempt access to restricted ports onyour network.Configuring a service to temporarily blocksitesConfigure the service to automatically block sites thatattempt to connect using a denied service. From PolicyManager:1 Double-click the service icon in the Services Arena.The Properties dialog box appears.2 Use the Incoming service Connections Are drop list toselect Enabled and Denied.3 Select the checkbox marked Auto-block sites thatattempt to connect via service, located at the bottom ofthe dialog box.Viewing the Blocked Sites listThe Blocked Sites list is a compilation of all sitescurrently blocked by the <strong>Firebox</strong>. Use <strong>Firebox</strong>Monitors to view sites that are automaticallyblocked according to a service’s property configuration.From <strong>System</strong> Manager, click the Blocked Site List tab atthe bottom of the graph. (You might need to use the arrowsto access this tab.)Integrating Intrusion DetectionIntrusion detection is an important component of adefense-in-depth security policy. A good intrusion detectionsystem (IDS) examines over time the source, destination,and type of traffic directed at your network andcompares it against known patterns of attack. When amatch occurs, it tells you the nature of the attack and recommendspossible courses of action.<strong>User</strong> <strong>Guide</strong> 193

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!