Symantec 11281411 Administration Guide - Page 52

LogAccessDenied, LogAccessDeniedWindowMinutes, Open the HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk

Page 52 highlights

52 Managing Symantec AntiVirus Enhancing server group security 2 Open the HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\ VirusProtect6\CurrentVersion\AccessList key. 3 Type LogAccessDenied as a new DWord. 4 Type 1 as the binary data associated with the LogAccessDenied DWord value to enable logging. 5 Close the registry editor. To set the frequency for logging unauthorized configuration change attempts 1 Start a registry editor, such as Regedt32. 2 Open the HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\ VirusProtect6\CurrentVersion\AccessList key. 3 Type LogAccessDeniedWindowMinutes as a new DWord. 4 Do one of the following: ■ To record every incident, type 0 as the binary data associated with the LogAccessDeniedWindowMinutes DWord value. The following message will appear when an unauthorized event occurs: Access denied to network communication from unauthorized address: where is the IP or IPX address of the computer that was denied access and is the port number that the computer attempted to use. ■ To record incidents based on a frequency in minutes, type a number (in minutes) as the binary data associated with the LogAccessDeniedWindowMinutes DWord value. The following message will appear when an unauthorized event occurs: Access denied to network communication from unauthorized addresses time(s) in the last minute(s). Most recent address: where is the frequency and the number of minutes, is the IP or IPX address of the computer that was denied access, and is the port number that the computer attempted to use. 5 Close the registry editor.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

52
Managing Symantec AntiVirus
Enhancing server group security
2
Open the HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\
VirusProtect6\CurrentVersion\AccessList key.
3
Type
LogAccessDenied
as a new DWord.
4
Type
1
as the binary data associated with the LogAccessDenied DWord value
to enable logging.
5
Close the registry editor.
To set the frequency for logging unauthorized configuration change attempts
1
Start a registry editor, such as Regedt32.
2
Open the HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\
VirusProtect6\CurrentVersion\AccessList key.
3
Type
LogAccessDeniedWindowMinutes
as a new DWord.
4
Do one of the following:
To record every incident, type
0
as the binary data associated with the
LogAccessDeniedWindowMinutes DWord value.
The following message will appear when an unauthorized event occurs:
Access denied to network communication from unauthorized address:
<IP or IPX address> <port> where <IP or IPX address> is the IP or IPX
address of the computer that was denied access and <port> is the port
number that the computer attempted to use.
To record incidents based on a frequency in minutes, type a number (in
minutes) as the binary data associated with the
LogAccessDeniedWindowMinutes DWord value.
The following message will appear when an unauthorized event occurs:
Access denied to network communication from unauthorized addresses
<N> time(s) in the last <N> minute(s). Most recent address: <IP or IPX
address> <port> where <N> is the frequency and the number of
minutes, <IP or IPX address> is the IP or IPX address of the computer
that was denied access, and <port> is the port number that the
computer attempted to use.
5
Close the registry editor.