Acl Syslog Forwarder - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
To import an ACL file to the Manager, do the following:
1
2
3
4
Note:
convertor tool for ACL rules (on page 101).

ACL Syslog Forwarder

Network Security Platform provides an optional ACL feature that will log packets that are
dropped or permitted based on your ACL rule(s). The Sensor forwards ACL logs to
Manager, where they are formatted and converted to Syslog messages and sent to the
configured Syslog server. You can then view the log from a third-party Syslog application.
The
admin domains have the option to include alerts from the corresponding child domains.
To configure Syslog forwarding of ACL logs, do the following:
1
2
3
4
5
6
IPS Settings > ACL > Import.
Select
Indicate whether to skip duplicate ACL definitions by selecting the check box.
Otherwise, leave the field unchecked.
Browse
Click
and select a file to import. Network Security Platform prompts you for the
file name.
Apply
Click
to accept the imported ACL file.
For more information on XML Convertor tool for ACL rules, see XML
ACL Syslog Notification
action enables ACL log forwarding. For Syslog forwarding, the
IPS Settings > ACL> ACL Syslog Notification
Select
Yes
Enable ACL Syslog Forwarder
Select
to
Select one or more of the following for
Current Admin Domain
: Sends notifications for ACL alerts in the current domain.
(Always enabled for the current domain.)
All Child Domain(s)
: Includes ACL alerts for all child domains of the current domain.
Enter one of the following in
Host IP Address
Host Name of the Syslog Server where alerts will be sent.
Port
Type the
on the target server which is authorized to receive Syslog messages.
Note:
The standard port for Syslog (514) is pre-filled in the field.
Facility.
Select the value for
choices are:
Security/authorization (code 4)
Security/authorization (code 10)
Log audit (note 1)
Log alert (note 1)
Clock daemon (note 2)
Local user 0 (local0)
Local user 1 (local1)
Local user 2 (local2)
Local user 3 (local3)
/NAC Settings >ACL >ACL Syslog Notification.
or
.
Enable Domain Notification
Syslog Server
:
This is the standard Syslog prioritization value. The
99
Managing IPS settings
:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents