Monitoring
This section provides information about the monitoring feature of NetworkShield Firewall 2006.
- Sessions
- Traffic usage
- Connections
- Events and Alerts
Sessions
NetworkShield Firewall allows you to monitor the activity of network objects by means of sessions and connections. Sessions represent the activity of a network object with an IP address. All connections established from one IP address via the NetworkShield Firewall server are considered one session. If a network client has more than one IP address, connections from each IP address will be considered as a separate session. A separate session will be created for connections established from the same IP address, but with the NetworkShield Firewall server.
The list of sessions is updated automatically at the specified period of time. If the client closes all connections of if client connections are closed by a timeout, the sessions is removed from the list.
There are three types of sessions: Direct, NAT, Route.
Direct sessions
Direct sessions occur when a client from any network establishes a connection with the NetworkShield Firewall server. Connections established from the NetworkShield Firewall servers to clients from any networks will be logged as a direct session. If a Redirect rule redirects connections with the NetworkShield Firewall server to internal servers in the Perimeter Network (aka DMZ), direct sessions are also created.
NAT sessions
NAT sessions occur when clients from private networks establish connections to resources from other networks and the network relationship is set as NAT in Network rules.
Route sessions
Route sessions occur when clients from one network establish connections to resources from other networks and the network relationship is set as Route in Network rules.
Starting and stopping monitoring sessions
To start monitoring sessions, click the Start on the toolbar. Click the Pause to pause monitoring. When paused, the session list will remain available for analysis and sessions will not be automatically updated. You can use the Reload button to update the list. Click the Stop to stop monitoring. It will clear the session list.
Traffic usage
The section of monitoring statistics of traffic usage rules contains the list of all active traffic usage rules and also the statistics available for them. The statistics is updated automatically in real time. It is possible to see it for a day, a week, a month, for the entire period or for any period of time. It is possible to view the detailed statistics by hours - for the last week, by days - for the last three months, by months - for the last six months.
Connections
The section of monitoring connections is used to monitor all connections established to the NetworkShield Firewall server. The connection list is updated in real time. The list shows all active connections from the moment when monitoring was started. It is necessary to monitor connections during the configuration of the system and for detecting problems in the network.
Starting and stopping monitoring Connections.
To start monitoring connections, click the Start on the toolbar. Click the Pause to pause monitoring. When paused, the session list will remain available for analysis and connections will not be automatically updated. You can use the Reload button to update the list. Click the Stop to stop monitoring. It will clear the connections list.
Events and Alerts
NetworkShield Firewall has an event log with all events that take place during the work of the system. The event log is necessary to detect errors in the work of the system and to fix them quickly. Events are loaded into the log when you open the list. Click the Refresh button to refresh the event list. There are two types of events: Security and System.
Security events
The Security events log contains events that affect the system security. For example, changing the settings of the system, attempts to log into the system as the administrator, user authentication in the system with NetworkShield Security Client.
System events
System events reflect the internal work of NetworkShield Firewall. For example, the work of the NetworkShield engine, the work of the NetworkShield Service, events related to registering the software.
|