12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using HostWatch- Show: Click this button to download and show a list of all current IPS signatures. After youdownload the signatures, you can look for signatures by signature ID.spamBlockerActivity since last restart- Number of messages that are identified as not spam, spam, bulk, or suspect e-mail.- Number of messages that are blocked and tagged.- Number of messages that are blocked or allowed because of a spamBlocker exceptions listthat you create (exceptions that you create to deny additional sites are sometimes known as ablacklist; exceptions that you create to allow additional sites are sometimes known as awhitelist).Using HostWatchHostWatch is a graphic user interface that shows the network connections between the trusted andexternal networks. HostWatch also gives information about users, connections, and network addresstranslation (NAT).The line that connects the source host and the destination host uses a color that shows the type of connection.You can change these colors. The default colors are:• Red — The Firebox® denies the connection.• Blue — The connection uses a proxy.• Green — The Firebox uses NAT for the connection.• Black — Normal connection (the connection has been accepted, and it does not use a proxy orNAT).Icons that show the type of service appear adjacent to the server entries for HTTP, Telnet, SMTP, and FTP.Domain name server (DNS) resolution does not occur immediately when you start HostWatch. WhenHostWatch is configured for DNS resolution, it replaces the IP addresses with the host or user names. Ifthe Firebox cannot identify the host or user name, the IP address stays in the HostWatch window.If you use DNS resolution with HostWatch, the management station can send a large number of NetBIOSpackets (UDP 137) through the Firebox. The only method to stop this is to turn off NetBIOS over TCP/IPin Windows.To start HostWatch, click the HostWatch icon in Firebox System Manager.Or select Tools > HostWatch.The HostWatch windowThe top part of the HostWatch window has two sides. You can set the interface for the left side. The rightside shows all other interfaces. HostWatch shows the connections to and from the interface configuredon the left side. To select an interface, right-click the current interface name. Select the new interface.Double-click an item on one of the sides to get the Connections For dialog box for connections thatinvolve that item. The dialog box shows information about the connection, and includes the IPaddresses, port number, time, connection type, and direction.<strong>User</strong> <strong>Guide</strong> 53

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!