Appendix A - Disposition Of Events For The Routefinder V3.Xx - Multitech RouteFinder RF850 User Manual

Multi-tech routefinder rf850: user guide
Hide thumbs Also See for RouteFinder RF850:
Table of Contents

Advertisement

Appendix A – Disposition of Events for
Revision History
Date
Revision
16-Aug-2004
R1
I.
Abstract
Disposition of Events
The LVPN RouteFinder 3.2x provides logging capabilities for various types of Access requests to the product.
The logging is classified as follows:
Inbound Access Requests (LO1.A)
Outbound Access Requests (LO1.B)
Access Requests to Firewall Violating Security Policy (LO1.C)
Access Requests Through Firewall Violating Security Policy (LO1.D)
Administrative Authentication Log (LO1.E)
Admin Port Access Requests (LO1.F)
Startup History (LO1.G)
User Defined Logs.
Fragmented Packets Log. (ST6)
Access Request
An Access Request is the first packet arriving at the interface to which the security policy is applied. All
subsequent packets that are part of an ongoing session are not termed as access requests since an
Access Request is the first packet that establishes a session. Logging of an Access Request implies
logging of the first packet of a session. Subsequent packets are not logged.
Inbound Access Request
Each access request from the external network to the box for any services hosted by the box or hosted
by an internal server and have to pass through the firewall is termed as an inbound access request.
Requests received on the WAN interface are termed inbound access request. If the WAN interface is
down and the dial backup PPP link is up, then a request received on the PPP interface to the firewall
will be termed inbound request access.
Access requests logged as Inbound Access Request correspond to LO1.A of Baseline module - version
4.0, ICSA Labs.
Figure 1 shows Inbound Access diagram
Figure 2 shows a snapshot of Inbound Access.
Figure 3 shows a snapshot of Inbound Access with DNAT and Connection Tracking.
Outbound Access Request
Each access request from the internal network (LAN/DMZ) to the external network (WAN) that passes
through the firewall is termed as an Outbound Access Request. All requests routed out through the
WAN interface to servers connected on or through the WAN Interface are considered Outbound
Access Requests.
Access requests logged as Outbound Access Request correspond to LO1.B of Baseline module -
version 4.0, ICSA Labs.
Figure 4 shows Outbound Access diagram.
Figure 5 shows a snapshot of Outbound Access
Figure 6 shows a snapshot of Outbound Access with connection tracking.
Multi-Tech Systems, Inc. RouteFinder RF850/860 User Guide (PN S000400E)
the RouteFinder v3.xx
For ICSA Certification
The Modular Firewall Certification Criteria
Baseline module - version 4.0
Remarks/Changes
Baseline document
Based on
Appendix A – Disposition of Events
149

Advertisement

Table of Contents
loading

This manual is also suitable for:

Routefinder rf860

Table of Contents