Symantec 10521146 Administration Guide - Page 375

Enable IPv4 Header Checksum Validation, Echo Operational Log to Syslog

Page 375 highlights

Index 375 drill-down reports (cont.) events per hour 233 events per month 233 flows by destination address 236 flows by destination port 237 flows by protocol 237 flows by source address 236 flows by source port 237 incident details 236 incidents list 232 incidents per day 232 incidents per hour 232 incidents per month 232 source destinations 234 top events 231 top level 230 types 229 E Echo Operational Log to Syslog setting node parameters 262 editing flow alert rules 156 in-line pairs 100 interface groups 98 LiveUpdates 273 location objects 84 monitoring interfaces on appliance nodes 96 monitoring interfaces on software nodes 90 network segments 108 node numbers 280 node passphrases 280 objects in topology tree 81 port mappings 178 protection policies 121 report schedules 224 response rules 134 root password on serial consoles 58 secadm password 58 signature variables 184 Smart Agent interfaces 107 Smart Agents 105 software nodes 86 user passphrases 57 user-defined signatures 181 EDP about Event Dispatch Protocol 29 communicating with Smart Agents 106, 284 communication by proxy 284 EDP (cont.) detection architecture 29 Network Security node passphrase 284 setting passphrases 106 setting port numbers 284 EDP Port Number setting node parameters 284 email configuring incidents 211 format 237 incident data 212 initiation request failure 200 notification failure 201 notification messages 142 Enable Flow Statistics Collection setting sensor parameters 163 Enable Full Packet Capture setting sensor parameters 163 Enable IPv4 Header Checksum Validation setting sensor parameters 168 Enable TCP Checksum Validation setting sensor parameters 169 Enable UDP Checksum Validation setting sensor parameters 169 Enable Watchdog Process setting node parameters 294 enabling Symantec Decoy Server 285 EngineUpdates about 269 errors compiling signatures 183 email initiation request failure 200 email notification failure 201 iButton 199 SNMP alert failure 201 SNMP initiation request failure 201 truncated SNMP message 201 ESP about node architecture 36 ethernet deploying failover groups through 294 Event Correlation 'Destination IP' Weight setting node parameters 217 Event Correlation 'Destination Port' Weight setting node parameters 218 Event Correlation 'Name' Weight setting node parameters 215

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

375
Index
drill-down reports (cont.)
events per hour
233
events per month
233
flows by destination address
236
flows by destination port
237
flows by protocol
237
flows by source address
236
flows by source port
237
incident details
236
incidents list
232
incidents per day
232
incidents per hour
232
incidents per month
232
source destinations
234
top events
231
top level
230
types 229
E
Echo Operational Log to Syslog
setting node parameters
262
editing
flow alert rules
156
in-line pairs
100
interface groups
98
LiveUpdates 273
location objects
84
monitoring interfaces on appliance nodes
96
monitoring interfaces on software nodes
90
network segments
108
node numbers
280
node passphrases
280
objects in topology tree
81
port mappings
178
protection policies
121
report schedules
224
response rules
134
root password on serial consoles
58
secadm password
58
signature variables
184
Smart Agent interfaces
107
Smart Agents
105
software nodes
86
user passphrases
57
user-defined signatures
181
EDP
about Event Dispatch Protocol
29
communicating with Smart Agents
106, 284
communication by proxy
284
EDP (cont.)
detection architecture
29
Network Security node passphrase
284
setting passphrases
106
setting port numbers
284
EDP Port Number
setting node parameters
284
email
configuring incidents
211
format 237
incident data
212
initiation request failure
200
notification failure
201
notification messages
142
Enable Flow Statistics Collection
setting sensor parameters
163
Enable Full Packet Capture
setting sensor parameters
163
Enable IPv4 Header Checksum Validation
setting sensor parameters
168
Enable TCP Checksum Validation
setting sensor parameters
169
Enable UDP Checksum Validation
setting sensor parameters
169
Enable Watchdog Process
setting node parameters
294
enabling
Symantec Decoy Server
285
EngineUpdates
about 269
errors
compiling signatures
183
email initiation request failure
200
email notification failure
201
iButton 199
SNMP alert failure
201
SNMP initiation request failure
201
truncated SNMP message
201
ESP
about node architecture
36
ethernet
deploying failover groups through
294
Event Correlation ±Destination IP° Weight
setting node parameters
217
Event Correlation ±Destination Port° Weight
setting node parameters
218
Event Correlation ±Name° Weight
setting node parameters
215