Re: FW-1 and "monitoring client"
From: Phil Hollows (phil_at_open.com)
Date: 06/11/04
- Next message: Stan Hilliard: "Re: My firewall intercepts probes from ARPA"
- Previous message: javaguy_in_wheaton: "Re: Help with creating SMB connection to a "safe" zone?"
- In reply to: Tom Aaqse: "FW-1 and "monitoring client""
- Next in thread: xdc: "Re: FW-1 and "monitoring client""
- Reply: xdc: "Re: FW-1 and "monitoring client""
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 11 Jun 2004 06:47:47 -0700
It depends on the sophistication of analysis you want. Security
information management correlation applications, such as Open's
Security Threat Manager (www.open.com) will analyze your FW logs (and
IDS, IPS, AV, routers, servers etc) in real-time, correlate the data
to identify threats and compromises (typically leveraging
vulnerability scan information). You can use their own console,
forward to HPOV or NetCool (or any SNMP capable console). These
products will talk syslog (or for check point, OPSEC to the device or
provider / 1 ), ODBC / JDBC, etc. All depends on the systems you're
looking at and the complexity of your environment. You obviously get
thorough reporting as well as alerting.
Benefits include earlier detection of attacks (typically in the
reconnaissance phase), false positive reduction and as a result more
time to spend on proactive measuers such as patching and policy
management.
Hope this helps
Phil Hollows
VP Security Products
OpenService, Inc (open)
www.open.com
508.599.2000
gxchristian@yahoo.co.uk (Tom Aaqse) wrote in message news:<dcb99e92.0406101213.1a9e81fb@posting.google.com>...
> Hello,
>
> We have some checkpoint firewalls that are sending their logs to a
> central console. We would like to have some kind of monitoring over
> the firewalls system based on "sampling" data each 5 or minutes, in a
> unattended fashion. Which would be the right direction to go?.
>
> Thanks.
- Next message: Stan Hilliard: "Re: My firewall intercepts probes from ARPA"
- Previous message: javaguy_in_wheaton: "Re: Help with creating SMB connection to a "safe" zone?"
- In reply to: Tom Aaqse: "FW-1 and "monitoring client""
- Next in thread: xdc: "Re: FW-1 and "monitoring client""
- Reply: xdc: "Re: FW-1 and "monitoring client""
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|