Administration Area
The Administration Area is where the
administrative functions can be configured and performed. The Administration
Area contains the following Sub-Areas:
-
System Information
-
Update
-
Manual Blocking
-
Diagnostics
-
System Control
-
IDM Properties
System Information (Administration | System
Information)
The system information panel lists configuration and system
information for the local sensor. As you can see in Figure 25-30, the system
information report includes the following information:
-
Sensor Version
-
Host Name
-
Organization Name
-
Organization ID
-
PostOffice Port
-
Web Server Port
-
CIDS Daemon Status
-
CIDS Connection Status
-
CIDS Version
-
IP Address
-
Netmask
-
Default Route
-
MAC Address
-
Hardware
-
Operating System
-
CPU Usage
-
Memory Usage
-
CIDS Logging Disk Usage
-
TAC Link
Update (Administration | Update)
The update configuration panel can be used to update the
software installed on the sensor. Updates can be initiated manually or they can
be scheduled, as shown in Figure 25-31. When performing an update or
configuring an automatic update, you must specify the FTP server address,
directory, user name, and password.
Manual Blocking (Administration | Manual Blocking)
Manual blocking can be initiated from the Administration
Area. You can specify the IP address or the network address you want to block
and the amount of time the address(s) should remain blocked, as shown in Figure
25-32.
Diagnostics (Administration | Diagnostics)
The diagnostics Sub-Area can be used to run a new
diagnostics test or to view the report generated when the last diagnostics
report was generated.
System Control (Administration | System Control)
The system control panel enables you to perform basic
administration of the sensor. This panel allows the administrator to
IDM Properties (Administration | System Control)
The IDM properties allow the
administrator to customize some configuration settings within the sensor itself.
Using the configuration panel in the Sub-Area Severity mapping, you can
customize the mapping of severity number (1–5) to the severity names. By
default, the mappings are as follows:
-
Informational Categorizes the event as informational in
nature and not a risk to security. These events are shown with a blue icon in
the IDS Event Viewer.
-
Low Categorized the event as mildly severe. These events are
displayed with a yellow icon in the IDS Event Viewer.
-
Medium Categorizes the event as a moderate risk. These
events are displayed with an orange icon in the IDS Event Viewer.
-
High risk. High-risk events are displayed with a red icon in
the IDS Event Viewer.
The second IDM properties TOC item is signature pagination.
This configures the number of signatures listed on a single display page when
viewing signature groups.
cp25 cr
345 times read
|
|
|
Did you enjoy this article?
(total 0 votes)
|