D-Link DFL-1600 User Manual page 208

Network security firewall
Hide thumbs Also See for DFL-1600:
Table of Contents

Advertisement

188
Once an IDS event occurs, the Intrusion Detection Rule is triggered. At
least one new event occurs within the Hold Time, 120 seconds, thus
reaching the log threshold level (at least 2 events has occurred). This
results in an e-mail to be sent, containing a summery of the IDS events.
Several more IDS events may occur after this, but to prevent flooding the
mail server, the firewall will wait for 600 seconds (10 minutes) before
sending a new e-mail, containing information about the new events. A
SMTP server is assumed to have been configured in the address book, with
an IP address object name "smtp-server".
WebUI
:
1. SMTP log receiver:
– adding a SMTP log receiver
System
Log and Event Receivers
SMTP Event Receiver:
General
Enter the following:
Name: smtp4IDS
SMTP Server: smtp-server
Server Port: 25 (by Internet standard)
Fill in alternative e-mail addresses in the edit boxes(up to 3 addresses can
be configured).
Sender: hostmaster
Subject: Log event from D-Link Firewall
Minimum Repeat Delay: 600
Hold Time: 120
Log Threshold: 2
Then click OK.
2. IDS Rules:
– Enabling logging in the "Log Settings" configuration page for a specific
IDS rule and using All receivers or specific receiver "smtp4IDS" config-
ured above as log receiver.
Chapter 19. Intrusion Detection System (IDS)
D-Link Firewalls User's Guide
Add

Advertisement

Table of Contents
loading

Table of Contents