Symantec 10521146 - Network Security 7120 Administration Manual page 151

Administration guide
Hide thumbs Also See for 10521146 - Network Security 7120:
Table of Contents

Advertisement

reached before the maximum time, then traffic record stops recording, but waits
until the maximum time has expired before starting a new record action. The
number of responses per incident is also determined by the response
configuration. The minimum delay between responses is 1 minute.
Note: This response action records only fully assembled packets from actual
flows, not malformed packets or packet fragments. You can view detected
packet contents in the Advanced tab of Event Details.
See
"Viewing event details"
Caution: Traffic record files are stored in the
can quickly fill the disk space, especially on a gigabit link. Make sure that this
directory contains sufficient disk space.
To enable traffic records
1
In the Network Security console, click Configuration > Response Rules.
2
In Response Rules, click the Response Action column of a rule.
3
In Configure Response Action, click Traffic Record.
4
Provide the following information:
Maximum packets to record: Enter the maximum number of packets
per incident of this response.
Maximum # of record actions: Enter the maximum number of records
per incident of this response.
Maximum time to record (mins): Enter the time in minutes that you
want Symantec Network Security to record per incident.
5
Click traffic record match parameters to select them:
Source IP: Click this parameter if you want to record only traffic with
the same source address as the triggering event.
Source Port: Click this parameter if you want to record only traffic with
the same source port as the triggering event.
Destination IP: Click this parameter if you want to record only traffic
with the same destination address as the triggering event.
Destination Port: Click this parameter if you want to record only
traffic with the same destination port as the triggering event.
Transport: Click this parameter if you want to record only traffic with
the same transport protocol (such as TCP, UDP or ICMP) as the
triggering event.
on page 197.
/usr/SNS/record
Responding
Setting response actions
directory, and
151

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security

Table of Contents