Cabletron Systems ETWMIM Especificações Página 1

Consulte online ou descarregue Especificações para Redes Cabletron Systems ETWMIM. Cabletron Systems ETWMIM Specifications Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 262
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
Table of Contents
Automated Security Manager Help..................................................................................................................1
Automated Security Manager Overview.................................................................................................1
Accessing Help........................................................................................................................................1
Table of Contents Tab ............................................................................................................................1
Search Tab .............................................................................................................................................2
Help Topics with Graphics......................................................................................................................2
NOTICE...............................................................................................................................................................3
Virus Disclaimer.....................................................................................................................................4
Restricted Rights Notice.........................................................................................................................4
CUSTOMER RELEASE NOTES.....................................................................................................................6
INTRODUCTION:..................................................................................................................................6
NetSight Automated Security Manager...................................................................................................7
SOFTWARE CHANGES AND ENHANCEMENTS.............................................................................7
SYSTEM REQUIREMENTS..................................................................................................................7
Supported Platforms..........................................................................................................................7
PRODUCT DEVICE/FIRMWARE SUPPORT:.....................................................................................8
Static Policies....................................................................................................................................8
CDP Implementation.........................................................................................................................9
Optimized Node/Alias Implementation...........................................................................................10
INSTALLATION INFORMATION:....................................................................................................11
Evaluation Copy..............................................................................................................................11
Upgrading Automated Security Manager........................................................................................12
CONFIGURATION CONSIDERATIONS...........................................................................................12
NetSight Automated Security Manager 2.2....................................................................................12
Dragon Intrusion Defense System...................................................................................................13
WindowsTM 2000...........................................................................................................................13
Devices............................................................................................................................................13
OPERATING SYSTEM PATCHES.....................................................................................................13
KNOWN RESTRICTIONS AND LIMITATIONS...............................................................................14
Install/Uninstall...............................................................................................................................14
NetSight Automated Security Manager..........................................................................................14
Help System....................................................................................................................................15
SUPPORTED MIBs..............................................................................................................................16
IMPORTANT URLS:............................................................................................................................16
GLOBAL SUPPORT.............................................................................................................................16
ADDENDUM:.......................................................................................................................................17
NetSight Automated Security Manager Installation.....................................................................................18
General Installation Information............................................................................................................18
System Requirements......................................................................................................................19
Evaluation Copy..............................................................................................................................19
NetSight Plugin Integration.............................................................................................................20
Windows Installation.............................................................................................................................20
Configuring the Environment..........................................................................................................21
Stopping the NetSight Server and Database (Windows).................................................................22
Installing Automated Security Manager (Windows).......................................................................22
Automated Security Manager Help
i
Vista de página 0
1 2 3 4 5 6 ... 261 262

Resumo do Conteúdo

Página 1 - Table of Contents

Table of ContentsAutomated Security Manager Help...

Página 2

Search Tab To search for specific instances of a term in all the help topics, click the right tab (magnifying glass) in the leftpanel. In the Find bo

Página 3

in the Activity Monitor has a status of Search Pending.Search Time (sec)The amount of time in seconds that it took for ASM to search for the source of

Página 4

Removes the selected entries event/action in the Activity Monitor. When the entry removed is the lastone for a particular incident, the associated Det

Página 5

Automated Security ManagerConfiguration WindowThis feature lets you configure Automated Security Manager (ASM) to automatically respond to a variety o

Página 6

Day and Time RangesThis view lets you identify specific time intervals that may be pertinent when applying threat responses.NOTE: The Day and Time Ran

Página 7

NameThis is a name that you can assign when defining a time interval.TimeThese controls let you select the time interval for this day and time range.D

Página 8

Add to ListAdds the current Days and Times definition to the Day/Time Ranges list.Remove from ListDeletes a Days and Times definition selected in the

Página 9 - Table of Contents Tab

Dragon has four default notification rules: netsight−atlas−asm−attacks, netsight−atlas−asm−compromise,netsight−atlas−asm−informational, and netsight−a

Página 10 - Help Topics with Graphics

MS−BACKDOOR3 MS−SQL:HAXOR−TABLE MS−SQL:PWDUMPMS−SQL:WORM−SAPPHIRE MS:BACKDOOR−BADCMD MS:BACKDOOR−DIRSMB:SAMBAL−SUCCESS SSH:HIGHPORT SSH:X2−CHRISSSH:X2

Página 11

number than all the others. If you want ASM to respond to these Event Categories last (since they aredeemed to be the least important), the Precedence

Página 12 - Restricted Rights Notice

NotificationsThis list shows all of the notifications that have been created.ButtonsCreateOpens the Create Notification window. This window takes one

Página 13

NOTICEEnterasys Networks reserves the right to make changes in specifications and other information contained inthis document without prior notice. Th

Página 14 - INTRODUCTION:

(E−Mail, Syslog, SNMP Trap, Script, Dragon, or Group).Used InSelect a Notification in the list, and click the Used In button to open a window that dis

Página 15 - SYSTEM REQUIREMENTS

Policy ListThis list contains the Policies that have been defined for ASM.ButtonsAdd to ListAdds the Policy name, typed into the associated field, to

Página 16 - Static Policies

NOTE: Sender Identifier names are case sensitive.Sender Identifier NameThe name of a Sender Identifier.Sender Identifier ListThis list contains the Se

Página 17 - CDP Implementation

Select a Sender Identifier in the list, and click the Used In button to open a window that displayswhich ASM rules are using the identifier.Sender Nam

Página 18

The Sender Name.Sender Name ListThis list contains the Sender Names that have been defined for ASM.ButtonsAdd to ListAdds the Sender Name, typed into

Página 19 - INSTALLATION INFORMATION:

Subnet NameThis is any name that you want to identify this subnet.Threat SubnetEnter the subnet that you want the ASM search scope to use when Dragon

Página 20 - CONFIGURATION CONSIDERATIONS

Adds the Threat Subnet and Mask, typed into the associated fields, to the list.Remove from ListRemoves a selected Threat Subnet and Mask from the list

Página 21 - OPERATING SYSTEM PATCHES

VLAN NameThe VLAN name.VLAN IDThe VLAN ID.VLAN ListThis list contains the VLANs that have been defined for ASM.ButtonsAdd to ListAdds the VLAN Name/VL

Página 22 - Install/Uninstall

ImportOpens a file browser where you can select a .pmd file to role names created in NetSight PolicyManager.Used InSelect a VLAN in the list, and clic

Página 23 - Help System

Search Scope DefinitionsThis view lets you select the devices that will be searched when Dragon notifies ASM of a threat. You can setthe search scope

Página 24 - GLOBAL SUPPORT

This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit.(http://www.openssl.org/)BOOTP Server SoftwareThe BOOTP

Página 25 - ADDENDUM:

Basic Search ScopeWith Basic Search Mode selected the Search Scope Definitions view lets you include or exclude selecteddevices/device groups from to

Página 26

search scope or click Exclude to designate your selection(s) as being specifically excluded in thesearch scope.You can repeatedly select devices/devic

Página 27 - Evaluation Copy

specific location−−for example, all the routers in a particular building. When a device type(Routers) and a location group (Building2) are both select

Página 28 - Windows Installation

Search ScopesThis panel lists the Search Scopes that can be associated with Search Scope Rules, which ultimatelydetermine the devices that will be sea

Página 29 - Configuring the Environment

ButtonsCreate (Group)Opens the Create Search Scope Group window where you can create groups of devices that will besearched when Dragon notifies ASM o

Página 30

Exclude Specific PortsThis view lets you select specific ports that you want to exempt from the actions by ASM to prevent shuttingdown critical ports.

Página 31 - Solaris Installation

MAC Address CountThis feature lets you distinguish between single−user ports and multi−user ports (routers). Whenchecked ASM will expand its query to

Página 32

Get Port InfoQueries the Port Elements and device(s) selected in the tree to obtain a list of available ports.ImportOpens a file browser to allow impo

Página 33 - Linux Installation

EnabledWhen checked, the action associated with the rule will be executed in response to an intrusion threat.Rule NameThis is the name assigned to the

Página 34

The event categories defined for the rule.Sender IdentifiersThe sender identifiers defined for the rule.PoliciesPort policies defined for this rule. D

Página 35 - Uninstalling on Windows

Modified, adapted, or combined with other computer software, provided that the modified,combined, or adapted portions of the derivative software incor

Página 36 - Uninstalling on Linux

Select Statistics WindowThis window lets you select the data elements that will appear in the Statistics area of the ASM ActivityMonitor window. It co

Página 37 - Training

Action Undo FailedThe number of entries in the table where a standard or custom undo has failed.Action Taken and UndoneThe number of entries in the ta

Página 38 - Getting Started with

Authorization/Device AccessUsers/Groups TabUse this tab to specify users who are authorized to access the NetSight database, and assign those users to

Página 39

Automatic User MembershipThe Automatic User Membership feature lets you specify an authorization group for users that login without having been previo

Página 40

Authorization GroupThe authorization group where the user is a member.Automatic MemberYes indicates that the associated user was not a previously auth

Página 41

User nameThe name used for this authorized user.Domain/Host nameThe user's domain/hostname that will be used to authenticate to the NetSight data

Página 42 - What's Next

Group NameThis is the name given to the group. When adding a group, you can enter any text string that isdescriptive of the members of this group.Capa

Página 43

Settings TabThe Settings tab configures how SNMP requests will be handled for users that are members of thisgroup.Allow Users to Configure SNMP Redire

Página 44

Authorization/Device AccessProfiles/Credentials TabNetSight applications access devices to control certain device functions (SNMP sets) and retrieve i

Página 45 - How to Check for Updates

Default Profile:This drop−down list lets you specify a profile that will be used by default to access a device.Profiles TableThis table lists all of t

Página 46

CUSTOMER RELEASE NOTESEnterasys NetSightTMAutomated Security ManagerVersion 2.2June, 2006INTRODUCTION:Refer to the Addendum section at the end of this

Página 47 - How to Configure Events

This table lists all of the credentials that have been created in the NetSight database. The public_v1credential is automatically created during Conso

Página 48

Click areas in the windows for more information.Profile NameA unique name (up to 32 characters) that you assign to this profile.When editing an existi

Página 49 - Removing an Event View

Max Access − used for write operations (set ) that require administrativeaccess.• Security LevelEach access level can be assigned a security level:Aut

Página 50 - How to Configure and Manage

Credential NameA unique name (up to 32 characters) that you assign to this access credential. You can definea new credential or select a name from the

Página 51 - Managing the Database

Automated Security Manager HelpAdd/Edit Credential Window 136

Página 52 - Viewing Client Connections

Authorization/Device AccessProfile/Device Mapping TabThis tab lets you define the specific Profiles to be used by users in each Authorization Group wh

Página 53 - Viewing Licenses

the profile used by the NetSight Administrator group. The Profile listed/selected for eachAuthorization Group column will be used by that group when c

Página 54 - Viewing Locks

Authorization/Device AccessManage SNMP Passwords TabThis tab lets you collectively manage the credentials that have been set on your network's de

Página 55 - Viewing Server Statistics

Authentication/PrivacyThe new SNMPv3 passwords that will be used for access to the associated device(s).Show Passwords in Clear TextWhen checked, the

Página 56 - Managing Credentials

Backup Database WindowUse the Backup Database window to save the currently active database to a file on the NetSight Serverworkstation. If the NetSigh

Página 57

NetSight Automated Security ManagerNetSight Automated Security Manager combines the features of a comprehensive intrusion detection system,such as Ent

Página 58 - Managing Profiles

Clean Up Incidents WindowThe Clean Up Incidents window lets you delete incidents from the Activity Monitor table based on incidentstatus. Use the chec

Página 59 - Managing Profiles 51

Configure Server WindowThe Configure Server window allows you to configure various NetSight Server parameters. The window has aright−panel view that c

Página 60 - Assigning Profiles to Devices

Total AllowedThe maximum number of client connections allowed for this plugin application. Select this field anduse the arrows to change the number, i

Página 61

Create/Edit Notification WindowThis window lets you create or edit notifications that are activated with your response to network threats. Thewindow t

Página 62

Specify information to include in E−Mail messageThese check boxes let you select elements of the event information to be added to your E−Mailnotificat

Página 63 - Traps and Informs•

ButtonsTestThis button allows sending a test syslog message to simulate a notification sent in response to anetwork threat.SNMP TrapThis window lets y

Página 64 - Managing Authorization Groups

This is the password (between 1 and 64 characters in length) that will be used to determine Privacy.This field is disabled for Privacy Type, None.Trap

Página 65 - Managing Users

The Program to run field does not allow using options. For example, you cannot entermyscript.bat –i <IP Address> −m <MAC Address> in the P

Página 66

Device IP devDevice Port portRule Name rnameAction actionDetails dtlsSNMP Parameters (note 1)SNMPv1, SNMPv2 SNMPv3Parameter Keyword Parameter KeywordS

Página 67 - How to Create and Edit

Example:Sender Name, Sender ID, Threat MAC, and SNMP Write are selected and the device isconfigured for SNMPv1 credentials, the information passed to

Página 68

PRODUCT DEVICE/FIRMWARE SUPPORT:Static PoliciesDevices that support Static Policies must be able to discard traffic at the role level and apply a Quar

Página 69

Privacy TypeDES or None, selected from this drop−down list. These settings are disabled if Authentication TypeNone is selected.Privacy PasswordThis is

Página 70

Automated Security Manager HelpGroup 153

Página 71

Create/Edit Rule WindowThe features and fields in the Create Rule and Edit Rule windows are identical, except for their title. Thesewindows are used t

Página 72

NameThe name given to this rule. The name can be any character string, excluding spaces, up to 64characters.Rule ConditionsThe following attributes ar

Página 73

different actions based on the device/device group selected here. For example, if you are creating arule with an action that applies a policy, you do

Página 74 - How to Import a Database

Match Selected − The event category is compared against one or more categoriesselected from the list.• Exclude Selected − The event category matches i

Página 75 - How to Manage SNMP Passwords

Match Any − This is an unconditional match for a currently applied policy.• Match Selected − A match occurs when the currently applied policy is one o

Página 76

Match Selected − The currently applied VLAN is compared against one or moreVLANs selected from the list.• Exclude Selected − The currently applied VLA

Página 77

Multi−User AuthenticationWhen the action for a rule is set to Apply Policy and the threat is located on a port on adevice that supports Multi−User Aut

Página 78

NOTE: When a custom action script does not specify the path for its output, the output is placedin the <install area>\Enterasys Networks\NetSigh

Página 79 - HOSTNAME=

FirmwareVersionMatrix E5 3.00.xxMatrix V22.03.xx2.04.xxVertical Horizon VH−2402S VH−2402−L3 VH−4802 VH−8TX1UM/MF2.05.191.00.162.05.052.04.07.08Roa

Página 80 - Firewall Considerations

notifications. In this window, you can select a Notification to edit, or click Create to open the CreateNotification window.Automated Security Manager

Página 81 - How to Set Options

Create/Edit Search ScopeThis window lets you create and name groups of devices that will be searched when Dragon notifies ASM ofa threat. It operates

Página 82 - Common Functions

Groups &DevicesThis panel shows the device tree for devices modeled in the Console database. You can expandbranches of the tree to select Devices/

Página 83

in both groups (Routers in Building2) will be included in the search scope.Resulting DevicesThe resulting list of devices that will be searched when D

Página 84 - Delete Table Entries

Create/Edit Search Scope RuleThis view lets you create rules that determine which search scope will be used when a specific threat arrives. Each searc

Página 85 - Clean Up Incidents

Match Selected − The Sender ID is compared against one or more Sender Identifiers selectedfrom the list.• Exclude Selected − The Sender ID matches if

Página 86

Edit Notifications WindowThis window lists all the notifications you have created, and lets you edit or remove a notification, or create anew one.Clic

Página 87 - Advanced Statistics Window

Edit EntryOpens the Edit Notification window for the notification selected in the list.Used InSelect a notification in the list, and click the Used In

Página 88 - Advanced Statistics Window 80

E−Mail Configuration WindowThe E−Mail Configuration window lets you create an E−Mail recipient list to use when configuring E−Mailnotification setting

Página 89 - \NetSight Console\logs

Automated Security Manager HelpE−Mail Configuration Window 171

Página 90

Optimized Node/Alias ImplementationAutomated Security Manager processes Dragon events by locating the intruder IP address stored in the eventand then

Página 91

Error removing Notification(s) WindowThis window automatically opens if you attempt to remove one or more notifications that are currently in useby AS

Página 92

Event ViewNetSight's Event View lets you view alarm, event, and trap information for the NetSight Console, networkdevices, and other NetSight app

Página 93

application (HPOV, NetSight Element Manager, etc.), you must shut it downbefore launching Console.Syslog TabThis tab maintains a record of all the BOO

Página 94

selected event or trap.ButtonsShow/Hide Acknowledged EventsThis button hides or shows items in the table that have been acknowledged by a check in the

Página 95

Event Details WindowThe Event Details window shows additional information about an event or trap selected in the Event View. Itcombines information ab

Página 96

ClientOnly applicable to Console events and shows the hostname of the source of the event.SeverityIndicates the potential impact of the event or trap.

Página 97

Event Log ViewerNetSight Options set limits on the size of log files that record events on your network. When the limit isreached, the information is

Página 98

UserAssociates an event with the user that performed the action that triggered the event.TypeIdentifies the type of information for this row (event, o

Página 99

Event View Manager WindowThe Event View Manager window lets you add your own tabs to the Event View panel to create custom tablesthat provide the info

Página 100 - Right−Click Menu

Title − The name that appears on the tab in the Event panel.• Log Managers − A comma−separated list of the Log Managers that contribute entries to the

Página 101

MIB Selection panel.Disable Node/Alias Learning −− It's important to make sure that inter−switch links are notlearning Node/Alias information, as

Página 102 - Configuration Window

This button applies the current Event Configurations, but leaves the Event View Manager windowopen to allow additional configuration.Automated Securit

Página 103 - Day and Time Ranges

New Log Manager WindowThe New Log Manager window lets you create local log managers to use when configuring Event Views. It isopened from the New butt

Página 104

Log Manager Parameters WindowThis window displays parameters for a selected log manager. It is opened from the Edit button when a logmanager is select

Página 105 - Event Categories

Poll IntervalThis field is only active when the Syslog or Traps Log Manager is selected. This is the time interval(in seconds) between retrieving info

Página 106

Custom Pattern Configuration WindowThis window lets you create a pattern that will be used to interpret information from a non−standard syslogfile. A

Página 107

Console 1.x Pattern − Parses files generated by Console 1.x• Console 2.0 Pattern − Parses files generated by Console, and its current plugins.• Fields

Página 108 - Notifications

Displays the the selected Fields and Delimiters that determine how each data element in the sampleline will be parsed and placed in a column in the Ev

Página 109

New/Edit (Event) View WindowThis window lets you define the name and any columns that you want to add to a new or existing Event View.It is opened fro

Página 110 - Policies

Automated Security Manager HelpNew/Edit (Event) View Window 190

Página 111 - Sender Identifiers

Open Log File WindowThis window lets you select a log file from either the client or server for viewing in the Event Log Viewerwindow. It also lets yo

Página 112

Table of ContentsNetSight Automated Security Manager InstallationSolaris Installation...

Página 113 - Sender Names

instructions included with the Entitlement that was sent to you. (For more information, see http://www.enterasys.com/products/management/.)Evaluation

Página 114 - Threat Subnets

Open Event Log on ServerThis browser opens with the default path set to the <install area>\Enterasys Networks\NetSightConsole\server\logs direct

Página 115

Automated Security Manager HelpOpen Event Log on Server 193

Página 116

Incident Test ToolThis tool lets you test and debug the search scopes and actions to verify ASM's response to an event.Click areas in the window

Página 117

Test response by directly invoking ASM − this level bypasses the SNMP trap mechanism, sendingthe trap directly to ASM. ASM processes the threat as if

Página 118 - Search Variables

ButtonsSend Incident to ASMSends the test (inform) message that you've configured to ASM. If you've configured your ASMRules correctly, the

Página 119 - Search Scope Definitions

ASM Log Entry Details WindowThis window displays detailed information about a specific trap/action entry selected in the AutomatedSecurity Manager Act

Página 120 - Basic Search Scope

TimestampShows the date and time when the event occurred.SourceShows the IP address of the host that was the source of the event.ClientShows the hostn

Página 121

Menu BarThe ASM menu bar provides access to tools and functions that help you maintain the security of yournetwork. ASM menus are available in several

Página 122 - Advanced Search Scope

FileDatabase > Import v1.5 ASM DatabaseOpens a file browser where you can select a Netsight Console version 1.5 database and import ASMcomponents i

Página 123

is dynamically updated as you set or change/define settings, always presenting the appropriate optionsas your configuration progresses. As you move th

Página 124 - Exclude Port Types

condition, possibly compromising the security of your network.Disable Log Entry Details. Under extreme network loads, you can improve ASM performance

Página 125 - Exclude Specific Ports

Opens your system's Web browser and takes you to the Enterasys Global Support Web page.Check for UpdatesAllows you to update Automated Security M

Página 126

Open Log File WindowThis window lets you select a log file from either the client or server for viewing in the Event Log Viewerwindow. It also lets yo

Página 127 - Rule Definitions

Open Event Log on ServerThis browser opens with the default path set to the <install area>\Enterasys Networks\NetSightConsole\server\logs direct

Página 128

Automated Security Manager HelpOpen Event Log on Server 205

Página 129

Options WindowThe Options window allows you to set options for NetSight functions on a suite−wide and per−applicationbasis. The Options window has a r

Página 130 - Select Statistics Window

Automated Security Manager OptionsAutomated Security Manager Options (Tools > Options) lets you define your preferences for ASMoperations. The righ

Página 131

ApplySets the currently defined settings and keeps the Options window open.OKSets the options and closes the window.CancelCancels any changes you have

Página 132 - Users/Groups Tab

Max Number of Outstanding ActionsThis parameter limits the number of outstanding (pending execution) actions.Max Number of Action per ThreatThis param

Página 133

Show Edit Mode Required DialogThe Edit Mode Required dialog appears if you try to make changes in the ASM Configurationwindow without first selecting

Página 134 - Add/Edit User Window

NOTE: Dragon EMS host names are casesensitive.Dragon EMS Host/IPThe Dragon EMS hostname or IP address.Dragon EMS ListThis list contains the Dragon EMS

Página 135 - Add/Edit Group Window

KNOWN RESTRICTIONS AND LIMITATIONSThe known restrictions and limitations for this release of NetSight Automated Security Manager are listedbelow. Solu

Página 136

SNMPThe SNMP view lets you specify options that define the ASM's SNMP polling parameters.Click areas of the window for more information.Number of

Página 137

Restore Database WindowUse the Restore Database window to restore the initial database or restore a saved database. Both functionswill cause all curre

Página 138 - Profiles/Credentials Tab

Server InformationWindowThe Server Information window lets you view and configure certain NetSight Server functions, includingmanagement of client con

Página 139

Current Client ConnectionsThis table lists all of the currently connected clients for this server, with the most recent connection at the top.The list

Página 140 - Add/Edit Profile Window

Disconnects the selected client. The client being disconnected receives a message saying that theirconnection will be terminated in 30 seconds. You mu

Página 141

Clears the log. If you want to retain a copy of the log that you are clearing, you must manually copythe date−stamped file in the <install area>

Página 142 - Add/Edit Credential Window

you modify that password, and also view and modify the connection URL for the database.PasswordClick Change to display a window where you can enter a

Página 143

User:The name of the user who initiated the lock.Authorization GroupThe authorization group the user belongs to.Client TypeThe type of client: Console

Página 144

Server Log TabThe Server Log displays all the events for the server. Server Log entries are listed by date and time, withnewer entries listed at the b

Página 145 - Profile/Device Mapping Tab

Use the drop−down list to select the number of lines you would like displayed in the log.Find:Enter the text or numeric value you want to find.Case Se

Página 146

GeneralProblem1:(Linux and UNIX only) You cannot specify a range of pages when printing from tables onUNIX or Linux systems. If you select Print from

Página 147 - Manage SNMP Passwords Tab

Display:Use the drop−down list to select the number of lines you would like displayed in the log.Filter:Enter the text or numeric value you want to us

Página 148

above the entries you can see the status of whether the entries are filtered or not filtered.Filter ButtonPerforms the filter and displays the results

Página 149 - Backup Database Window

Select this button to view the current day's log. The name of the log and the path to where it is locatedis displayed in the field to the right.P

Página 150 - Clean Up Incidents Window

Server License LimitationsInformation on the selected server license:whether the server accepts connections from remote clients.• the maximum number o

Página 151 - Configure Server Window

generate a product license. Refer to the instructions included with the License Entitlement ID that wassent to you.) Click Update. The license file wi

Página 152

NetSight Server Statistics WindowUse this window to view NetSight Server statistics. You can access the window by clicking the Server Statsbutton in t

Página 153 - E−Mail Notification

snmptrapd.conf Text Editor WindowThis window lets you edit the content of the snmptrapd.conf file to define credentials that will be used byConsole wh

Página 154

myauthpasswordMD5 or SHA − authentication type and authentication password(optional parameter − do not use when authentication is notused)myprivpasswo

Página 155 - SNMP Trap

either Remote Desktop or athird−party program, you can restartsnmptrapd as follows:Go to the Taskbar NotificationArea of the remote desktop.a. Locate

Página 156

Specify Program for Action/Undo WindowWhen creating a rule, this window lets you:customize the response to an event by selecting a program to be execu

Página 157

Return to the Search tab, clear the entry and click Search. Go back to theContents and the navigation will work correctly.Problem 3: Help does not lau

Página 158

myscript.bat such as:C:\Program Files\My Custom Files\myscript.bat –i %1 −m %2".Uncheck all but the Threat IP and Threat MAC checkboxes and selec

Página 159

Action actionDetails dtlsSNMP Parameters (note 1)SNMPv1, SNMPv2 SNMPv3Parameter Keyword Parameter KeywordSNMPReadsnmp="v1"roSNMPRead,SNMPWri

Página 160

And, for a script named myscript.bat, the resulting script command would be executed as:C:\Program Files\Enterasys Networks\NetSightConsole\server\plu

Página 161 - Group 153

ToolbarThe ASM toolbar provides easy access to some of the more commonly used Automated Security Managermenu functions. Some Toolbar buttons may not b

Página 162 - Create/Edit Rule Window

Automated Security Manager HelpToolbar 236

Página 163 - Rule Conditions

Updates Available WindowNetSight applications provide an easy way to download product updates using a web update operationaccessed from Help > Che

Página 164

DetailsOpens the NetSight Updates Details window where you can see details on what each update includes.Automated Security Manager HelpUpdates Availab

Página 165

Usage WindowThis window lets you view where rule variables are in use by ASM rules. The title of the window changesdepending on the rule variable you

Página 166

Reference InformationThe References help folder contains information that is referenced by other help topics.Double−click the References help folder i

Página 167 - Specify Action to take

Disable Log Entry DetailsIf you experience ASM performance problems while under extreme network load, you can improveperformance by disabling Log Entr

Página 168

For information regarding the latest software available, recent release note revisions, or if you requireadditional assistance, please visit the Enter

Página 169 - Specify Action for Undo

802.1x Authentication (PAE)Port Access Entity module for managing IEEE 802.1X.Check this MIB to find other occurrences of an IP address or MAC address

Página 170 - Specify Action for Undo 162

the Node/Alias (ctAlias) MIB.IGMP StandardMIB module for IGMP Management, it contains an IGMP Interface Table, having one row for eachinterface on whi

Página 171 - Create/Edit Search Scope

Check this MIB to find other occurrences of an IP address or MAC address within your search scope.The values returned by searching this MIB are often

Página 172

NetSight − Supported MIBsA B C D E F G H I J L M N O P Q R S T U V W ZAACCOUNTING−CONTROL−MIB ADSL−LINE−MIB ADSL−TC−MIBAGENTX−MI

Página 173

ctron−dcm−mib ctron−deciv−router−mib ctron−device−mibctron−dhcp−mib ctron−dlsw−mib ctron−download−mibctron−elan−mib ctron−environment−mib ctron−ethern

Página 174 - Create/Edit Search Scope Rule

DDECNET−PHIV−MIB DIAL−CONTROL−MIB DIRECTORY−SERVER−MIBDISMAN−EVENT−MIB DISMAN−EXPRESSION−MIB DISMAN−NSLOOKUP−MIBDISMAN−PING−MIB DISMAN−SCHEDULE−MIB DI

Página 175

Ffast−ethernet−mib FLOW−METER−MIB FRAME−RELAY−DTE−MIBFDDI−SMT73−MIB FR−ATM−PVC−SERVICE−IWF−MIB FRNETSERV−MIBFIBRE−CHANNEL−FE−MIB FR−MFR−MIBGgarp−mibHH

Página 176 - Edit Notifications Window

Llan−emulation−client−mibMMAU−MIB MIP−MIB MIOX25−MIBModem−MIB MTA−MIBNnetlink−specific−mib NETWORK−SERVICES−MIB NOTIFICATION−LOG−MIBnetwork−diags−mib

Página 177

RRADIUS−ACC−CLIENT−MIB RADIUS−ACC−SERVER−MIB RADIUS−AUTH−CLIENT−MIBRADIUS−AUTH−SERVER−MIB RDBMS−MIB repeater−mib−2repeater−rev4−mib RFC1065−SMI RFC115

Página 178 - E−Mail Configuration Window

UUDP−MIB UPS−MIB ups2−mibusm−target−tag−mibVVRRP−MIB v2h124−24−mib.txtWwrs−master−mib WWW−MIBZziplock−mibAutomated Security Manager HelpU 251

Página 179

NetSight Automated Security Manager InstallationNOTE: When this topic is opened from the CD−ROM, the links from this topic to other help topics willno

Página 180

Traps and InformsSNMP Notification messages (Traps and Informs) provide the mechanism for one SNMP application to notifyanother SNMP application that

Página 181 - Event View

myUser security user namemyauthpasswordMD5 or SHA − authentication type and authentication password(optional parameter − do not use when authenticatio

Página 182 - Right−click Menu

myauthpasswordMD5 or SHA − authentication type and authentication password(optional parameter − do not use when authentication is notused)myprivpasswo

Página 183 - \NetSight Atlas

Before you install Automated Security Manager, it is recommended that you read the NetSight AutomatedSecurity Manager Release Notes. You can also acce

Página 184 - Event Details Window

In the Automated Security Manager main window, select Tools > Server Information.1. In the Server Information window, click the License tab.2. Sel

Página 185

a Windows platform system, you need to:Configure the Environment• Stop the NetSight Server and Database (Windows)• Once your system is properly config

Página 186 - Event Log Viewer

Table of ContentsHow to Configure and Manage the NetSight ServerChanging the Database Password...

Página 187

Select the Advanced tab and click the Settings button in the "Performance" section. The PerformanceOptions window opens.2. Select the Advanc

Página 188 - Event View Manager Window

No server or database components will be installed. This requires that an AutomatedSecurity Manager Client and Server has been installed on another sy

Página 189

NOTE: You may encounter a Java exception during the install whenbecoming the root user with the su − command. Be sure thatyour system's root envi

Página 190

The NetSight Automated Security Manager Installer leads you through a series of windows that askyou for all the information required in order to insta

Página 191 - New Log Manager Window

following procedures assume that the CD drive from which you are installing is physically attached to thesystem where ASM is being installed. The user

Página 192 - Log Manager Parameters Window

License Text −− You will need to enter the license text that you received when you generatedthe Automated Security Manager license. (When you purchase

Página 193

Go to the Taskbar Notification Area of your desktop (on the lower right of your screen, unless you'verelocated your Taskbar).1. Right−click the S

Página 194

Start the Uninstaller by issuing the command:./UninstallAutoSecMgr.sh2. SupportTo locate product specific information, refer to the Enterasys website:

Página 195

Getting Started withAutomated Security ManagerAutomated Security Manager (ASM) can help you manage responses to serious network security threats. This

Página 196

There are two ways to configure SNMPTrap information: Using the Trap Receiver Configuration View or bymanually adding user information to the snmptrap

Página 197 - New/Edit (Event) View Window

Table of ContentsHow To Send a Test Incident to ASM...

Página 198

You can also type user credentials directly into the snmptrapd.conf Text area to add entries to theconfiguration file. The format for user information

Página 199 - Open Log File Window

Open a Web browser and navigate to Dragon. The following URL opens the Dragon user interface: https://<Dragon IP address>/dragon1. Enter th

Página 200 - Open Event Log on Server

Enter a Name for your new Alarm and click Save.f. Deploy your new trap configuration.Click DEPLOYMENT in the left panel.a. Click Deploy to activate yo

Página 201 - Open Event Log on Server 193

Dragon has four default notification rules: netsight−atlas−asm−attacks, netsight−atlas−asm−compromise,netsight−atlas−asm−informational, and netsight−a

Página 202 - Incident Test Tool

How To Use the Automated Security ManagerThe How To help folder contains help topics that give you instructions for performing tasks in NetSightAutoma

Página 203 - Manager\Resources

How to Check for UpdatesNetSight applications provide an easy way to access and download product updates using a web updateoperation. You can perform

Página 204 - Buttons 196

The Updates Available window opens where you can view the new updates that are available fordownload. Use the checkboxes to select the updates you wis

Página 205 - ASM Log Entry Details Window

How to Configure EventsYou can use the Event View Manager window to add your own views (tabs) to the Event View panel. Youcan create custom tables tha

Página 206

If the Available Log Managers table lists a log that you want to add to this tab, select that log managerfrom the list and click . The selected log m

Página 207 - Menu Bar

If the Available Log Managers table lists a log that you want to add to this tab, select that log managerfrom the list and click . The selected log m

Página 208

Table of ContentsAutomated Security ManagerConfiguration WindowButtons...

Página 209 - Applications

How to Configure and Managethe NetSight ServerUse the Server Information window to manage various NetSight Server functions including viewing serverin

Página 210

Click OK.6. Managing the DatabaseUse the Database tab in the Server Information window to change the database server password andconnection URL, as we

Página 211

Select the Database tab.2. In the NetSight Data Set Operations section, click Backup. The Backup Database window opens.3. The Database Path field disp

Página 212

In the Current Client Connections table, select the client that you want to disconnect and click theDisconnect button.3. The client being disconnected

Página 213 - Open Event Log on Server 205

Upgrading a Console LicenseOn UNIX and Linux systems only, you can use the Change License function to upgrade a Console licensefrom a Standalone to a

Página 214 - Options Window

Revoking a LockUse the following steps to revoke a lock.Select Tools > Server Information from the menu bar. The Server Information window opens.1.

Página 215 - Common Buttons

How To Configure Profiles and CredentialsUse this tab to manage credentials that define the access privileges required for SNMPv1, SNMPv2c, andSNMPv3,

Página 216 - Action Limits

Select a Privacy Type (DES or None). Privacy settings are disabled when the AuthenticationType is set to None.d. Type the same password (between 1 and

Página 217 - Dialog Boxes

Managing ProfilesProfiles are assigned to device models in the NetSight database. They identify the credentials that are used forthe various access le

Página 218 - Dragon EMS

Click Delete. The selected profile is removed from the table.3. Automated Security Manager HelpManaging Profiles 51

Página 219

Table of ContentsCreate/Edit Rule Window...

Página 220

How To Configure Profile/Device MappingUse the Profile/Device Mapping tab to specify which profile will be used by each Authorization Group whencommun

Página 221 - Restore Database Window

How to Configure the SNMPTrap ServiceConsole's SNMPTrap Service (snmptrapd) must know the user credentials of a sending agent (on the device)befo

Página 222 - Server Information

Restarting snmptrapd ServiceDepending on the system where the NetSight Server is running and your preference, there are several ways torestart the snm

Página 223

For related information:Traps and Informs• Automated Security Manager HelpRestarting snmptrapd Service 55

Página 224

How to Manage Users and GroupsUse the Users and Groups tab (via the Authorization/Device Access tool) to specify users who are authorizedto access the

Página 225 - Database Tab

Never Redirect SNMP to the NetSight Server − SNMP requests are always madefrom the client system.• These settings have no effect when both the client

Página 226 - Locks Tab

Click or choose Authorization/Device Access from the Tools menu. The Authorization/DeviceAccess window opens with the Users/Groups tab selected.1. C

Página 227

How to Create and EditAutomated Security Manager RulesAutomated Security Manager Rules serve two distinct functions:Examine the source of the threat (

Página 228 - Server Log Tab

Select the Event Categories that will result in applying the action for this rule. To berecognized by ASM, the text string in the event message sent b

Página 229

Match Any − This is an unconditional match for a currently applied VLAN. • Match Selected − The currently applied VLAN is compared against one or more

Página 230

Table of ContentsMenu BarApplications...

Página 231

Custom Action:Check Custom Action and click Edit to open the Specify Program for Action window where you cancustomize the response to an event by sele

Página 232 - License Tab

Threat MAC thmacDevice IP devDevice Port portRule Name rnameAction actionDetails dtlsSNMP Parameters (note 1)SNMPv1, SNMPv2 SNMPv3Parameter Keyword Pa

Página 233

When Unformatted without spaces is selected, the parameters will be passed asspace delimited, unformatted text, without keywords. For this option, you

Página 234

Automated Security Manager HelpHow to Create and Edit Automated Security Manager Rules 65

Página 235

How to Import a DatabaseYou can import a NetSight database (Console release 1.5) containing previously configured ASM componentsinto the NetSight 2.2

Página 236

How to Manage SNMP PasswordsUse this tab to collectively manage the credentials that have been set on your network's devices.Instructions for:Set

Página 237 - Restarting snmptrapd Service

ButtonsTestThis button lets you test to verify that the credential in the "Use for Set" column can access theapplicable MIBs on the device.A

Página 238

How To Send a Test Incident to ASMThis tool lets you test and debug the search scopes, and actions to verify ASM's response to an event. You canp

Página 239

Trap Receiver − This is the system where the SNMPTrap Service is running.• If necessary, edit the SNMPTrapd.conf file to configure user credentials in

Página 240

Server Configuration ConsiderationsThis Help topic provides configuration information for the NetSight Server, such as running the server in anon−DNS

Página 241

Table of ContentsNetSight − Supported MIBsC...

Página 242

Edit the HOSTNAME variable at the top of the file to:HOSTNAME="<server IP address>"For example, HOSTNAME="123.123.123.123"2.

Página 243

How to Set OptionsUse the Options window to set options for NetSight functions on a suite−wide and per−application basis. TheOptions window has a righ

Página 244 - Toolbar 236

How to Set Automated Security Manager OptionsAutomated Security Manager Options (Tools > Options) let you define your preferences for ASM operation

Página 245 - Updates Available Window

Click Apply or OK.5. Dialog BoxesThis view lets you select whether certain dialog boxes are shown or ignored.Select Tools > Options in the menu bar

Página 246 - Updates Available Window 238

Using the ASM Activity MonitorThe Activity Monitor opens when you launch Automated Security Manager (ASM). It contains a log of ASMactivities, and pro

Página 247 - Usage Window

Clean Up IncidentsYou can delete incidents from the Activity Monitor based on incident status.Click the Clean Up Incidents button below the Activity M

Página 248 - Reference Information

NetSight Automated Security Manager WindowsThe Windows help folder contains help topics describing NetSight Automated Security Manager windowsand thei

Página 249 - Disable Log Entry Details

Advanced Statistics WindowThis window provides advanced server statistics that are useful as a troubleshooting tool. You can access thiswindow by clic

Página 250

Automated Security Manager HelpAdvanced Statistics Window 80

Página 251

Automated Security Manager Activity MonitorIn addition to the Menu Bar and Toolbar, the Automated Security Manager Activity Monitor window consistsof

Página 252

Automated Security Manager HelpWelcome to the online help system for Enterasys NetSightTM Automated Security Manager (ASM). All ASMdocumentation is av

Página 253 - NetSight − Supported MIBs

The panels in the upper half of the view can be closed by clicking the button. The Operation Mode andStatistics Summary panels are restored by selec

Página 254

button) to show only the traffic light indicator in the upper right corner. A drop−down menu letsyou make selections as shown here:ASM can be Disable

Página 255

Device/Port, Rule Name, Action, Details, Last Update and Search Time columns.Show Excluded − when checked, the table contains entries for when an IP a

Página 256

not been confirmedyet.The status for thisentry was Action inProgress when theASM Operation Modechanged to Disabled,Search Only orConsole was exitedand

Página 257

Port already disabled,Custom action failed• Policy already appliedto port, Custom actionfailed• PVID already appliedto port, Custom actionfailed• Poli

Página 258

SNMP Sets fail (Writeparameters do notmatch the device),Custom actionexecuted• Device not in database,Custom actionexecuted• Policy not on device,Cust

Página 259

not exist on deviceCurrent PVID settingdoes not agree withASM action taken (thisincludes PVID andtagging parameters)• Current port state doesnot agree

Página 260 - Traps and Informs

Undo Action button;Custom Undo ActionexecutedAction undone byTimer; Custom UndoAction executed• ASM Action was set toNone; Custom Actionwas executed a

Página 261 - SNMPv3 Informs

Blank Custom Action OnlyASM Action was set toNone; Custom actionexecuted• ASM Action was set toNone; Custom Actionfailed• NOTE: This status onlyappear

Página 262 - Restart the SNMPTrap Service

Port QueryPending• Blank Search PendingSearch for this entry is in thesearch queue.Blank Action PendingAction for this entry is in theaction queue..Bl

Comentários a estes Manuais

Sem comentários