12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Setting Blocked SitesSend SNMP trapWhen you enable this check box, the Firebox sends an event notification to the SNMPmanagement system. The SNMP trap makes sure that traffic matches allowed values. Anexample of criteria it examines is a threshold limit.Send notificationWhen you enable this check box, the Firebox sends a notification when a packet is deniedbecause of your blocked port configuration. You can configure the Firebox to do one of theseactions:- E-mail The Firebox sends an e-mail message when the event occurs. Set the e-mail addressin the Notification tab of the Log Server user interface.- Pop-up Window The Firebox makes a dialog box appear on the management station whenthe event occurs.Setting Launch Interval and Repeat CountYou can control the time of the notification, together with the Repeat Count, as follows:Launch IntervalThe minimum time (in minutes) between different notifications. This parameter prevents morethan one notification in a short time for the same event.Repeat CountThis counts how frequently an event occurs. When this gets to the selected value, a specialrepeat notifier starts. This notifier makes a repeat log entry about that specified notification.Notification starts again after this number of events.Here is an example of how to use these two values. The values are configured as:• Launch interval = 5 minutes• Repeat count = 4A port space probe starts at 10:00 a.m. and continues each minute. This starts the logging and notificationmechanisms. These are the times and the actions that occur:1 10:00—Initial port space probe (first event)2 10:01—First notification starts (one event)3 10:06—Second notification starts (reports five events)4 10:11—Third notification starts (reports five events)5 10:16—Fourth notification starts (reports five events)The launch interval controls the time intervals between the events 1, 2, 3, 4, and 5. This was set to 5 minutes.Multiply the repeat count by the launch interval. This is the time interval an event must continue tostart the repeat notifier.Blocking sites temporarily with policy settingsYou can use the policy configuration to block sites that try to use a denied service:1 From Policy Manager, double-click the policy icon.The Properties dialog box appears.2 On the Policy tab, make sure you set the Connections Are drop-down list to Denied.3 On the Properties tab, select the check box Automatically block sites that attempt to connect.The IP address from the denied packets are added to the temporary Blocked Sites list for 20 minutes (by default).<strong>User</strong> <strong>Guide</strong> 141

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!