10 Select Event Signatures to receive a signature with the event.
To receive a signature, the Platform Agent on the event source must be configured properly.
For more information, see
11 Click Save.
5.3.1 Port Configuration and Port Forwarding
The default port on which Identity Audit listens for messages from the s is port 1289. When the port
is set, the system checks whether the port is valid and open.
Binding to ports less than 1024 requires root privileges. Instead, Novell recommends that you use a
port greater than 1024. You can change the source devices to send to a higher port or use port
forwarding on the Identity Audit server.
To change the event source to send to a different port:
1 Log into the event source machine.
2 Open the
operating system:
Linux:
Windows:
NetWare:
Solaris:
3 Set the LogEnginePort parameter to the desired port.
4 Save the file.
5 Restart the Platform Agent. The method varies by operating system and application. Reboot the
machine or refer to the application-specific documentation on the
Site (http://www.novell.com/documentation)
To configure port forwarding on the Identity Audit server:
1 Log into the Identity Audit server operating system as
2 Open the file
3 Add the following command near the end of the bootup process:
iptables -A PREROUTING -t nat -p protocol --dport incoming port -j DNAT --
to-destination IP:rerouted port
where protocol is tcp or udp, incoming port is the port on which the messages are arriving, and
IP:rerouted port are the IP address of the local machine and an available port above 1024
4 Save the changes.
5 Reboot. If you cannot reboot immediately, run the
line.
5.3.2 Client Authentication
Event sources send their data over an SSL connection, and the Client authentication setting for the
Identity Audit server determines what kind of authentication is performed for the certificates from
the s on the event sources.
42
Identity Audit Guide
Section 5.2, "Managing Event Sources," on page
file for editing. The file is in a different location depending on the
logevent
/etc/logevent.conf
C:\WINDOWS\logevent.cfg
SYS:\etc\logevent.cfg
/etc/logevent.conf
/etc/init.d/boot.local
Novell Documentation Web
for more instructions.
(or
to
root
su
for editing.
command above from a command
iptables
40.
).
root
Need help?
Do you have a question about the IDENTITY AUDIT 1.0 - GUIDE and is the answer not in the manual?