WatchGuard x1000 Betriebsanweisung
Chapter 14: Generating Reports of Network Activity
250
WatchGuard Firebox System
Denied Authentication Detail
A detailed list of failures to authenticate, sorted by
time. The fields are Date, Time, Host, and User.
time. The fields are Date, Time, Host, and User.
Consolidated sections
Network Statistics
A summary of statistics on one or more log files for
all devices being monitored.
all devices being monitored.
Time Summary – Packet Filtered
A table, and optionally a graph, of all accepted
connections distributed along user-defined
intervals and sorted by time. If you choose the
entire log file or specific time parameters, the
default time interval is daily. Otherwise, the time
interval is based on your selection.
connections distributed along user-defined
intervals and sorted by time. If you choose the
entire log file or specific time parameters, the
default time interval is daily. Otherwise, the time
interval is based on your selection.
Host Summary – Packet Filtered
A table, and optionally a graph, of internal and
external hosts passing packet-filtered traffic, sorted
either by bytes transferred or number of
connections.
external hosts passing packet-filtered traffic, sorted
either by bytes transferred or number of
connections.
Service Summary
A table, and optionally a graph, of traffic for all
services sorted by connection count.
services sorted by connection count.
Session Summary – Packet Filtered
A table, and optionally a graph, of the top
incoming and outgoing sessions, sorted either by
byte count or number of connections. The format of
the session is: client -> server : service. If the
connection is proxied, the service is represented in
all capital letters. If the connection is packet
filtered, Historical Reports attempts to resolve the
server port to a table to represent the service name.
If resolution fails, Historical Reports displays the
port number.
incoming and outgoing sessions, sorted either by
byte count or number of connections. The format of
the session is: client -> server : service. If the
connection is proxied, the service is represented in
all capital letters. If the connection is packet
filtered, Historical Reports attempts to resolve the
server port to a table to represent the service name.
If resolution fails, Historical Reports displays the
port number.