WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide WatchGuard Firebox System 4.6 User Guide

watchguard.com
from watchguard.com More from this publisher
13.07.2015 Views

Setting up the LiveSecurity Event Processorcontrold -nt-install2 Start the LiveSecurity Event Processor service.Select Start => Settings => Control Panel. Double-click Services. Click WG LiveSecurity EventProcessor. Click Start. You can also restart your computer. The service starts automaticallyevery time the host reboots.3 To remove the Event Processor as a service, stop it using Control Panel. Then, atthe command line, type:controld -nt-removeIn addition, if the Event Processor is running as a service and you are using pop-upnotifications, you must ensure that the service can interact with the Desktop:1 In Control Panel, double-click Services. In Windows 2000, click Start => Settings =>Control Panel => Administrative Tools => Services.2 Click WG LiveSecurity Event Processor. Click Startup.3 Verify that the Allow Service To Interact With Desktop checkbox is enabled.If the Event Processor was running, restart it after saving the changes.Interactive mode from a DOS windowOn the Event Processor:1 Open a DOS window.Select Start => Programs => Command Prompt.2 Change directories to the WatchGuard installation directory.The default installation directory is C:\Program Files\WatchGuard.3 Type the following command:controld -NT-interactiveThe Event Processor starts. You can minimize the DOS window. Do not, however, close thewindow. Closing the DOS window halts the Event Processor.Viewing the Event ProcessorWhile the LiveSecurity Event Processor is running, a Firebox-and-traffic icon appearsin the Windows Desktop tray. To view the Event Processor, right-click the tray iconand select Log Center.If the Event Processor icon is not in the tray, in the Control Center, select LiveSecurity=> Logging => Event Processor Interface. To start the Event Processor interface whenyou log in to the system, add a shortcut to the Startup folder in the Start menu. TheWatchGuard installation program does this automatically if you set up logging.Starting and stopping the Event ProcessorThe Event Processor starts automatically when you start the host on which it resides.However, it is possible to stop or restart the Event Processor from its interface at anytime. Open the Event Processor interface:• To start the Event Processor, select File => Start Service.• To stop the Event Processor, select File => Stop Service.74

Setting global logging and notification preferencesSetting the log encryption keyThe log connection (but not the log file) between the Firebox and an Event Processoris encrypted for security purposes. Both the Management Station and the EventProcessor must possess the same encryption key.You must enter an encryption key in order for the Event Processor to receivelogs from the Firebox. It must be the same key used when adding an EventProcessor to the Management Station.From the LiveSecurity Event Processor:1 Select File => Set Log Encryption Key.2 Enter the log encryption key in both text boxes. Click OK.Setting global logging and notification preferencesThe LiveSecurity Event Processor lists the connected Firebox and displays its status. Ithas three control areas:• Log File tab – Specify the maximum number of records stored in the log file.• Reports tab – Schedule regular reports of log activity.• Notification tab – Control to whom and how notification takes place.Together, these controls set the general parameters for most global event processingand notification properties.Setting the interval for log rolloverLog records accumulate at different rates depending on the volume of network trafficand the logging and notification settings configured for services and properties. Youcan control when the Event Processor rolls log entries from one file to the next usingthe Log Files tab in the Event Processor. For example, configure the Event Processorto roll over from one log file to the next by time interval, number of entries, or both.From the Event Processor interface:1 Click the Log Files tab.2 For a time interval, enable the By Time Interval checkbox. Select the frequency.Use the Schedule First Log Roll For drop list to select a date. Use the scroll controlor enter the first time of day.3 For a record size, enable the By Number of Entries checkbox. Use the scroll controlor enter a number of log record entries.The Approximate Size field changes to display the approximate file size of the final log file. For adetailed description of each control, right-click it, and then select What’s This?.4 Click OK.The Event Processor Interface closes and saves your entries. New settings take effectimmediately.User Guide 75

Setting up the LiveSecurity Event Processorcontrold -nt-install2 Start the LiveSecurity Event Processor service.Select Start => Settings => Control Panel. Double-click Services. Click WG LiveSecurity EventProcessor. Click Start. You can also restart your computer. The service starts automaticallyevery time the host reboots.3 To remove the Event Processor as a service, stop it using Control Panel. Then, atthe command line, type:controld -nt-removeIn addition, if the Event Processor is running as a service and you are using pop-upnotifications, you must ensure that the service can interact with the Desktop:1 In Control Panel, double-click Services. In Windows 2000, click Start => Settings =>Control Panel => Administrative Tools => Services.2 Click WG LiveSecurity Event Processor. Click Startup.3 Verify that the Allow Service To Interact With Desktop checkbox is enabled.If the Event Processor was running, restart it after saving the changes.Interactive mode from a DOS windowOn the Event Processor:1 Open a DOS window.Select Start => Programs => Command Prompt.2 Change directories to the <strong>WatchGuard</strong> installation directory.The default installation directory is C:\Program Files\<strong>WatchGuard</strong>.3 Type the following command:controld -NT-interactiveThe Event Processor starts. You can minimize the DOS window. Do not, however, close thewindow. Closing the DOS window halts the Event Processor.Viewing the Event ProcessorWhile the LiveSecurity Event Processor is running, a <strong>Firebox</strong>-and-traffic icon appearsin the Windows Desktop tray. To view the Event Processor, right-click the tray iconand select Log Center.If the Event Processor icon is not in the tray, in the Control Center, select LiveSecurity=> Logging => Event Processor Interface. To start the Event Processor interface whenyou log in to the system, add a shortcut to the Startup folder in the Start menu. The<strong>WatchGuard</strong> installation program does this automatically if you set up logging.Starting and stopping the Event ProcessorThe Event Processor starts automatically when you start the host on which it resides.However, it is possible to stop or restart the Event Processor from its interface at anytime. Open the Event Processor interface:• To start the Event Processor, select File => Start Service.• To stop the Event Processor, select File => Stop Service.74

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!