WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide WatchGuard Firebox System 4.6 User Guide

watchguard.com
from watchguard.com More from this publisher
13.07.2015 Views

WatchGuard logging architecturelog messages to the second Event Processor. It continues through the list until it findsan Event Processor capable of recording events.Multiple Event Processors operate in failover mode, not redundancymode—that is, events are not logged to multiple Event Processorssimultaneously; they are logged only to the primary Event Processor unlessthat host becomes unavailable. Then the logs are passed on to the nextavailable Event Processor according to the order of priority. As soon as ahigher-priority Event Processor becomes available again, the logs areshifted to that host. The highest-ranking Event Processor available alwaysreceives the logs.The LiveSecurity Event Processor software must be installed on each EventProcessor. For more information, see “Setting up the LiveSecurity EventProcessor” on page 73.WatchGuard logging architectureThe flexible architecture of the Firebox System makes it possible to separate thelogging and notification responsibilities to multiple machines. By default, the PolicyManager and the log and notification application – the LiveSecurity Event Processor– are installed on the same computer. You can, however, install the Event Processorsoftware on a separate or multiple computers.You must complete the following tasks to configure the firewall for logging andnotification:Policy Manager- Add logging and notification host(s)- Customize preferences for services and packet handling options- Save the configuration file with logging properties to the FireboxLiveSecurity Event Processor- Install the software on each Event Processor- Set global logging and notification preferences for the host- Set the log encryption key on the Event Processor identical to the key set inPolicy Manager.Designating Event Processors for a FireboxYou should have at least one Event Processor to run the WatchGuard Firebox System.The default primary Event Processor is the Management Station, which is set whenyou run the QuickSetup wizard. You can specify a different primary Event Processoras well as multiple backup Event Processors.• IP address of each Event Processor• Encryption key to secure the connection between the Firebox and EventProcessors• Priority order of primary and backup Event Processors70

Designating Event Processors for a FireboxAdding an Event ProcessorFrom Policy Manager:1 Select Setup => Logging.2 Click Add.3 Enter the IP address to be used by the Event Processor.4 Enter the encryption key that secures the connection between the Firebox and theEvent Processor.The default encryption key is the monitoring passphrase set in the QuickSetup wizard. You mustuse the same log encryption key for both the Firebox and the LiveSecurity Event Processor.5 Click OK.Repeat until all primary and backup Event Processors appear in the LiveSecurity EventProcessors list.Enabling Syslog loggingNote that Syslog logging is not encrypted; therefore, do not set the Syslog server to ahost on the External interface. From Policy Manager:1 Select Setup => Logging.The Logging Setup dialog box appears.2 In the Logging Setup dialog box, click the Syslog tab.3 Enable the Enable Syslog Logging checkbox.4 Enter the IP address of the Syslog server.Editing an Event Processor settingModify an Event Processor entry to change the log encryption key. From PolicyManager:1 Select Setup => Logging.The Logging Setup dialog box appears.2 Click the host name. Click Edit.3 Modify the IP address or log encryption key fields. Click OK.You must use the same log encryption key for both the Firebox and the LiveSecurity EventProcessor. To change the log encryption key on the Event Processor, see “Setting the logencryption key” on page 75.Removing an Event ProcessorRemove an Event Processor when you no longer want to use it for any loggingpurpose. From Policy Manager:1 Select Setup => Logging.The Logging Setup dialog box appears.2 Click the host name. Click Remove.User Guide 71

<strong>WatchGuard</strong> logging architecturelog messages to the second Event Processor. It continues through the list until it findsan Event Processor capable of recording events.Multiple Event Processors operate in failover mode, not redundancymode—that is, events are not logged to multiple Event Processorssimultaneously; they are logged only to the primary Event Processor unlessthat host becomes unavailable. Then the logs are passed on to the nextavailable Event Processor according to the order of priority. As soon as ahigher-priority Event Processor becomes available again, the logs areshifted to that host. The highest-ranking Event Processor available alwaysreceives the logs.The LiveSecurity Event Processor software must be installed on each EventProcessor. For more information, see “Setting up the LiveSecurity EventProcessor” on page 73.<strong>WatchGuard</strong> logging architectureThe flexible architecture of the <strong>Firebox</strong> <strong>System</strong> makes it possible to separate thelogging and notification responsibilities to multiple machines. By default, the PolicyManager and the log and notification application – the LiveSecurity Event Processor– are installed on the same computer. You can, however, install the Event Processorsoftware on a separate or multiple computers.You must complete the following tasks to configure the firewall for logging andnotification:Policy Manager- Add logging and notification host(s)- Customize preferences for services and packet handling options- Save the configuration file with logging properties to the <strong>Firebox</strong>LiveSecurity Event Processor- Install the software on each Event Processor- Set global logging and notification preferences for the host- Set the log encryption key on the Event Processor identical to the key set inPolicy Manager.Designating Event Processors for a <strong>Firebox</strong>You should have at least one Event Processor to run the <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>.The default primary Event Processor is the Management Station, which is set whenyou run the QuickSetup wizard. You can specify a different primary Event Processoras well as multiple backup Event Processors.• IP address of each Event Processor• Encryption key to secure the connection between the <strong>Firebox</strong> and EventProcessors• Priority order of primary and backup Event Processors70

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!