11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 11: Intrusion Detection and PreventionThe <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong> default packet handlingoptions provide a basic intrusion detection system byblocking common and readily recognizable attacks such asIP address spoofing and linear port space probes. Theintrusion detection capabilities of the <strong>Firebox</strong>, however, arenecessarily limited. The primary function of your firewallis to examine and either allow or deny packets. Little extrabandwidth is available to conduct sophisticated analysis oftraffic patterns.LiveSecurity Service subscribers can download a command-lineutility called the <strong>Firebox</strong> <strong>System</strong> IntrusionDetection <strong>System</strong> Mate (fbidsmate) that integrates the <strong>Firebox</strong>with most commercial and shareware IDS applications.You use the fbidsmate utility to configure your IDSto run scripts that query the <strong>Firebox</strong> for information.Because versions are available for Win32 (Windows NT,Windows 2000, and Windows XP), SunOS, and Linux operatingsystems, you can select whatever IDS application bestsuits your security policy and network environments.Working with an external IDS application, the <strong>Firebox</strong> canautomatically add sites to the Blocked Sites list. Timeoutsand blocked site exceptions work exactly as they do forsites blocked using default packet handling options. Sitesadded to the Blocked Sites list appear in the <strong>Firebox</strong> MonitorsBlocked Sites tab. In addition, you can use the utility toadd explanatory log messages to the log file which can subsequentlybe used for reports.Because the fbidsmate utility is external to the <strong>Firebox</strong>, nochanges in the configuration file are required, nor is thereanything additional to configure using Policy Manager.To obtain a copy of the fbidsmate command-line utility thatmatches the operating system on which your IDS applicationis running, log in to yourLiveSecurity Service account at:https://www.watchguard.com/support194 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!