WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

Clearing the ARP CacheLearning more about a traffic log messageTo learn more about a traffic log message, you can:Copy the IP address of the source or destinationMake a copy of the source or destination IP address of a traffic log message, and paste it into adifferent software application. To copy the source IP address, right-click the message, and selectSource IP Address > Copy Source IP Address. To copy the destination IP address, right-clickthe message, and select Destination IP Address > Copy Destination IP Address.Ping the source or destinationTo ping the source or destination IP address of a traffic log message, do this: Right-click themessage, and select Source IP Address > Ping or Destination IP Address > Ping. A pop-upwindow shows the results.Trace the route to the source or destinationTo use a traceroute command to the source or destination IP address of a traffic log message, dothis: Right-click the message, and select Source IP Address > Trace Route or Destination IPAddress > Trace Route. A pop-up window shows you the results of the traceroute.Temporarily block the IP address of the source or destinationTo temporarily block all traffic from a source or destination IP address of a traffic log message,do this: Right-click the message, select Source IP Address > Block: [IP address] or DestinationIP Address > Block: [IP address]. The length of time that an IP address is temporarily blocked bythis command is set in Policy Manager. To use this command you must give the configurationpassword.Clearing the ARP CacheThe ARP (Address Resolution Protocol) cache on the Firebox® keeps the hardware addresses (also knownas MAC addresses) of TCP/IP hosts. Before an ARP request starts, the system makes sure that a hardwareaddress is in the cache. You must clear the ARP cache on the Firebox after installation when your networkhas a drop-in configuration.1 From Firebox System Manager, select Tools > Clear ARP Cache.2 Type the Firebox configuration passphrase. Click OK.This flushes the cache entries.When a Firebox is in drop-in mode, this procedure clears only the content of the ARP table and not theMAC table. The oldest MAC entries in the MAC table are removed if the table has more than 2000 entries.If you want to clear the MAC table, you must restart the Firebox.Using the Performance ConsoleThe Performance Console is a Firebox® utility that you use to make graphs that show how different partsof the Firebox are operating. To get the information, you define the counters that identify the informationthat is used to make the graph.Types of countersYou can monitor these types of performance counters:40 WatchGuard System Manager

Using the Performance ConsoleSystem InformationShow how the CPU is used.InterfacesMonitor and report on the events of selected interfaces. For example, you can set up a counterthat monitors the number of packets a specified interface receives.PoliciesMonitor and report on the events of selected policies. For example, you can set up a counterthat monitors the number of packets that a specified policy examines.VPN PeersMonitor and report on the events of selected VPN policies.TunnelsMonitor and report on the events of selected VPN tunnels.Defining countersTo identify a counter for any of the categories:1 From Firebox System Manager, select the Performance Console icon. Or, selectTools > Performance Console.The Add Chart window appears.User Guide 41

Clearing the ARP CacheLearning more about a traffic log messageTo learn more about a traffic log message, you can:Copy the IP address of the source or destinationMake a copy of the source or destination IP address of a traffic log message, and paste it into adifferent software application. To copy the source IP address, right-click the message, and selectSource IP Address > Copy Source IP Address. To copy the destination IP address, right-clickthe message, and select Destination IP Address > Copy Destination IP Address.Ping the source or destinationTo ping the source or destination IP address of a traffic log message, do this: Right-click themessage, and select Source IP Address > Ping or Destination IP Address > Ping. A pop-upwindow shows the results.Trace the route to the source or destinationTo use a traceroute command to the source or destination IP address of a traffic log message, dothis: Right-click the message, and select Source IP Address > Trace Route or Destination IPAddress > Trace Route. A pop-up window shows you the results of the traceroute.Temporarily block the IP address of the source or destinationTo temporarily block all traffic from a source or destination IP address of a traffic log message,do this: Right-click the message, select Source IP Address > Block: [IP address] or DestinationIP Address > Block: [IP address]. The length of time that an IP address is temporarily blocked bythis command is set in Policy Manager. To use this command you must give the configurationpassword.Clearing the ARP CacheThe ARP (Address Resolution Protocol) cache on the Firebox® keeps the hardware addresses (also knownas MAC addresses) of TCP/IP hosts. Before an ARP request starts, the system makes sure that a hardwareaddress is in the cache. You must clear the ARP cache on the Firebox after installation when your networkhas a drop-in configuration.1 From Firebox System Manager, select Tools > Clear ARP Cache.2 Type the Firebox configuration passphrase. Click OK.This flushes the cache entries.When a Firebox is in drop-in mode, this procedure clears only the content of the ARP table and not theMAC table. The oldest MAC entries in the MAC table are removed if the table has more than 2000 entries.If you want to clear the MAC table, you must restart the Firebox.Using the Performance ConsoleThe Performance Console is a Firebox® utility that you use to make graphs that show how different partsof the Firebox are operating. To get the information, you define the counters that identify the informationthat is used to make the graph.Types of countersYou can monitor these types of performance counters:40 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!