D-Link DFL-700 Product Manual - Page 25

Enable Logging, Enable E-mail alerting for IDS/IDP events

Page 25 highlights

The D-Link DFL-700 specifies a number of events that can be logged. Some of these events, such as startup and shutdown, are mandatory and will always generate log entries. Other events, for instance when allowed connections are opened and closed, are configurable. It is also possible to have E-mail alerting for IDS/IDP events to up to three email addresses. Enable Logging Follow these steps to enable logging. Step 1. Enable SYSLog by checking the SYSLog box. Step 2. Fill in your first SYSLog server as SYSLog server 1. If you have two SYSLog servers, you have to fill in the second one as SYSLog server 2. You must fill in at least one SYSLog server for logging to work. Step 3. Specify what facility to use by selecting the appropriate SYSLog facility. Local0 is the default facility. Click the Apply button below to apply the settings or click Cancel to discard changes. Enable Audit Logging To start auditing all traffic through the firewall, follow the steps below. This is required when running third party log analyzers on the logs or to see how much traffic specific connections account for. Follow these steps to enable auditing. Enable SYSLog by checking the Enable Audit Logging box. Click the Apply button below to apply the settings or click Cancel to discard changes. Enable E-mail alerting for IDS/IDP events Follow these steps to enable E-mail alerting. Step 1. Enable E-mail alerting by checking the Enable E-mail alerting for IDS/IDP events checkbox. Step 2. Choose the sensitivity level. Step 3. In the SMTP Server field, fill in the SMTP server to which the DFL-700 will send the e-mail alerts. Step 4. Specify up to three valid email addresses to receive the e-mail alerts. Click the Apply button below to apply the settings or click Cancel to discard changes.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138

The D-Link DFL-700 specifies a number of events that can be logged. Some of these
events, such as startup and shutdown, are mandatory and will always generate log entries.
Other events, for instance when allowed connections are opened and closed, are configurable.
It is also possible to have E-mail alerting for IDS/IDP events to up to three email addresses.
Enable Logging
Follow these steps to enable logging.
Step 1.
Enable SYSLog by checking the
SYSLog
box.
Step 2.
Fill in your first SYSLog server as
SYSLog server 1
.
If you have two SYSLog
servers, you have to fill in the second one as
SYSLog server 2
.
You must fill in at least
one SYSLog server for logging to work.
Step 3.
Specify what facility to use by selecting the appropriate SYSLog facility. Local0 is
the default facility.
Click the
Apply
button below to apply the settings or click
Cancel
to discard changes.
Enable Audit Logging
To start auditing all traffic through the firewall, follow the steps below. This is required
when running third party log analyzers on the logs or to see how much traffic specific
connections account for.
Follow these steps to enable auditing.
Enable SYSLog by checking the
Enable Audit Logging
box.
Click the
Apply
button below to apply the settings or click
Cancel
to discard changes.
Enable E-mail alerting for IDS/IDP events
Follow these steps to enable E-mail alerting.
Step 1.
Enable E-mail alerting by checking the
Enable E-mail alerting for IDS/IDP
events
checkbox.
Step 2.
Choose the sensitivity level.
Step 3.
In the
SMTP Server
field, fill in the SMTP server to which the DFL-700 will send
the e-mail alerts.
Step 4.
Specify up to three valid email addresses to receive the e-mail alerts.
Click the
Apply
button below to apply the settings or click
Cancel
to discard changes.