WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

Setting up the Firebox for a Designated Log Server2 Click Configure. Click Add.The Add Event Processor dialog box appears.3 In the Log Server Address box, type the IP address of the Log Server you want to use.4 In the Encryption Key and Confirm boxes, type the Log Server encryption key. The allowed rangefor the encryption key is 8–32 characters. You can use all characters but spaces and slashes (/ or \).5 Click OK. Click OK to close the Configure Log Servers dialog box. Click OK to close the LoggingSetup dialog box.6 Save the changes to the Firebox to begin logging.You can verify that the Firebox is logging correctly. From WSM, select Tools > Firebox System Manager.In the Detail section on the left, next to Log Server, you should see the IP address of the log host.Setting Log Server priorityIf the Firebox cannot connect to the Log Server with the highest priority, it connects to the subsequentLog Server in the priority list. If the Firebox examines each Log Server in the list and cannot connect, ittries to connect to the first Log Server in the list again. You can create a priority list for Log Servers.1 From Policy Manager, select Setup > Logging.The Logging Setup dialog box appears.2 Click Configure.The Configure Log Servers dialog box appears.3 Select a Log Server from the list in the Configure Log Servers dialog box. Use the Up and Downbuttons to change the order.Activating syslog loggingSyslog is a log interface developed for UNIX but also used by a number of computer systems. You canconfigure the Firebox to send log information to a syslog server. A Firebox can send log messages to aLog Server and a syslog server at the same time, or send log messages to one or the other. Syslog logmessages are not encrypted. We recommend that you do not select a host on the external interface.1 From Policy Manager, select Setup > Logging.The Logging Setup dialog box appears.2 Select the Send Log Messages to the Syslog server at this IP address check box.3 In the address box, type the IP address of the syslog server.4 Click Configure.The Configure Syslog dialog box appears.84 WatchGuard System Manager

Setting up the Firebox for a Designated Log Server5 For each type of log message, select the syslog facility to which you want it assigned. Forinformation on types of log messages, see “Types of Log Messages” on page 90.The syslog facility refers to one of the fields in the syslog packet and to the file the syslog is sent to. You can useLocal0 for high priority syslog messages, such as alarms. You can use Local1- Local 7 to assign priorities for othertypes of log messages (with lower numbers having greater priority). See your syslog documentation for moreinformation on logging facilities.6 Click OK. Click OK to close the Logging Setup dialog box.7 Save your changes to the Firebox.Enabling advanced diagnosticsYou can select the level of diagnostic logging to write to your log file or to Traffic Monitor. We do not recommendthat you set the logging level to the highest level unless a technical support representativetells you to in order to troubleshoot a problem. It can cause the log file to fill up very quickly. It can alsomake an high load on the Firebox.1 From Policy Manager, select Setup > Logging.The Logging Setup dialog box appears.User Guide 85

Setting up the Firebox for a Designated Log Server5 For each type of log message, select the syslog facility to which you want it assigned. Forinformation on types of log messages, see “Types of Log Messages” on page 90.The syslog facility refers to one of the fields in the syslog packet and to the file the syslog is sent to. You can useLocal0 for high priority syslog messages, such as alarms. You can use Local1- Local 7 to assign priorities for othertypes of log messages (with lower numbers having greater priority). See your syslog documentation for moreinformation on logging facilities.6 Click OK. Click OK to close the Logging Setup dialog box.7 Save your changes to the Firebox.Enabling advanced diagnosticsYou can select the level of diagnostic logging to write to your log file or to Traffic Monitor. We do not recommendthat you set the logging level to the highest level unless a technical support representativetells you to in order to troubleshoot a problem. It can cause the log file to fill up very quickly. It can alsomake an high load on the Firebox.1 From Policy Manager, select Setup > Logging.The Logging Setup dialog box appears.<strong>User</strong> <strong>Guide</strong> 85

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!