Firewall Analyzer
-Firewall Log Analysis Software
|
|
Firewall Analyzer FAQGeneral Product Information
Installation
Configuration
Reporting
CheckPoint Firewall Reports
Cisco PIX Firewall Reports
NetScreen Firewall Reports (Syslog)
Other Firewall Reports (Sonicwall, Fortigate, and all other firewalls that support WELF)
Can't find an answer here? Check out the Firewall Analyzer user forum Is a trial version of Firewall Analyzer available for evaluation? Yes, a 30-day free trial version can be downloaded here. The trial version is fully functional for 30 days, after which you cannot restart the Firewall Analyzer server. Does the trial version have any restrictions? The trial version is a fully functional version of Firewall Analyzer. When the trial period expires, you cannot restart the server. Do I have to reinstall Firewall Analyzer when moving to the fully paid version? No, you do not have to reinstall or shut down the server. You just need to enter the new license file in the Upgrade License box. What other devices can Firewall Analyzer report on? Apart from reporting on most enterprise firewalls, Firewall Analyzer can also analyze logs and generate specific reports on Squid Proxy servers, and Radius servers. I don't have a firewall, proxy server, or Radius server. Can I still use this product? You can still use Firewall Analyzer to simulate firewall logs and see how reports will look like when real-time data is used. Click the Simulate link in the Settings tab to begin sending sample log files to Firewall Analyzer. How many users can access the application simultaneously? This depends only on the capacity of the server on which Firewall Analyzer is installed. The Firewall Analyzer license does not limit the number of users accessing the application at any time. How secure is the data that is sent to the web browser over the Internet? Data sent from Firewall Analyzer is normally not encrypted and hence is readable if intercepted. Firewall Analyzer runs in a web browser. Does that mean I can access it from anywhere? Yes. As long as the web browser can access the server on which Firewall Analyzer is running, you can work with Firewall Analyzer from any location. How do I buy Firewall Analyzer? You can buy Firewall Analyzer directly from the Manageengine Online Store, or from a reseller near your location. Is there a limit on the number of users or web sites that I can monitor? There is no license restriction on the number of users or web sites that you can monitor. However, you may face performance issues when using lower end machines to run Firewall Analyzer. What are the recommended system requirements for Firewall Analyzer? It is recommended that you install Firewall Analyzer on
a machine with the following configuration: Look up System Requirements to see the minimum configuration required to install and run Firewall Analyzer. Does the installation of Firewall Analyzer make any changes to the firewall server configuration? The installation of Firewall Analyzer does not make any changes to the firewall server configuration. Can I install Firewall Analyzer as a root user? Firewall Analyzer can be started as a root user, but all file permissions will be changed, and later you cannot start the server as another user. When I try to access the web client, another web server comes up. How is this possible? The web server port you have selected during installation is possibly being used by another application. Configure that application to use another port, or change the Firewall Analyzer web server port. Is a database backup necessary, or does Firewall Analyzer take care of this? The archiving feature in Firewall Analyzer automatically stores all logs received in zipped flat files. You can configure archiving settings to suit the needs of your enterprise. Apart from that, if you need to backup the database, which contains processed data from firewall logs, you can run the database backup utility, BackupDB.bat/.sh present in the <FirewallAnalyzer_Home>/troubleshooting directory. How to configure Firewall Analyzer as service in Linux, after installation? Normally, the Firewall Analyzer is installed as a service. If you have installed as an application and not as a service, you can configure it as a service any time later. The procedure to configure as service, start and stop the service is given below. To configure Firewall Analyzer as a service after installation, execute the following command. Can I use Java installation present in the Firewall Analyzer server machine? If yes, what is the procedure? Yes, you can use Java installation present in the Firewall Analyzer server machine. The procedure is given below:
Note: %JAVA_HOME% is the folder where JRE is installed on the server machine e.g., C:\Program Files\Java\j2re1.4.1_01
Note: %JAVA_HOME% is the folder where JRE is installed on the server machine e.g., /usr/local/j2sdk1.4.1_01
How do I see session information of all users registered to log in to Firewall Analyzer? The session information for each user can be accessed from the User Management page. Click the View link under Login Details against each user to view the active session information and session history for that user. How do I configure my firewall to produce log files in WELF? Firewalls usually need to be configured specifically to generate log files in WELF. The Configuring Firewalls section includes configuration instructions for some of the firewalls supported by Firewall Analyzer. My firewall cannot export logs. How do I configure Firewall Analyzer to report on my firewall? You can set up Firewall Analyzer to import the logs from the firewall at periodic intervals. Does Firewall Analyzer store raw logs? Raw logs are archived periodically, and stored as zipped flat files. You can load these archived log files into Firewall Analyzer at any time and generate reports based on them. How to assign Unassigned Protocols to Protocols and Protocol Groups? Protocols in Reports You can view the port details of theunassigned protocols:
We have configured the generally used protocols as Groups like Mail, Web, FTP, Telnet, etc. However, you can group the unknown protocols as per your requirement. Configuring Unassigned Protocol will be a one-time activity.
Note:Once you assign the protocols, the reports will show the assigned protocols and the newly assigned protocols under their appropriate protocol group only from the assigned time. You will see the unassigned protocols in the reports generated earlier to the assigned time. If you find that the reports based on ports, please assign specific protocols to the corresponding port numbers and create a custom report to view the details. Checking the port numbers
Graphs are empty if no data is available. If you have started the server for the first time, wait for at least one minute for graphs to be populated. What are the types of report formats that I can generate? Reports can be generated in HTML, CSV, and PDF formats. All reports are generally viewed as HTML in the web browser, and then exported to CSV or PDF format. However, reports that are scheduled to run automatically, or be emailed automatically, are generated only as PDF files. Are IP addresses automatically resolved? IP addresses are automatically resolved by connecting to the network DNS server. Why are some traffic values shown as 0.0MB or 0.00%? Since Firewall Analyzer processes log files as and when they are received, traffic values of 0.0MB or 0.0% may be displayed initially when the amount of traffic is less than 10KB. In such a case, wait until more data is received to populate the report tables. What are the different formats in which reports can be exported? Reports can be exported as PDF or CSV files. However, reports are emailed only as PDF files. Why do the intranet reports show zero results? Verify if intranets have been configured correctly. If you have specified IP addresses that are not actually behind the firewall, you will get zero values in the reports. Why don't trend reports take time values or top-n values into account? Trend reports show historical data for the corresponding traffic statistics shown in the report. Hence time changes from the Global Calendar, or top-n value changes from the Show bar on the report, do not affect these reports. Why the Un-used Rules Report is empty? To view the "Un Used Rules Reports", you need to configure Firewall Analyzer to fetch rules from device via Telnet or SSH. After this configuration the reports will be available. However, this advanced feature is available only for Premium License Users of Firewall Analyzer. CheckPoint Firewall Reports All the traffic reports are showing bytes value as zero? Make sure you have set the Track value of your rules to Account in your CheckPoint management station. You can use Check Point Smart console to do the same. You can set the track value as Account for the rules that are allowing the traffic through your firewalls. I am not getting VPN reports for CheckPoint firewall? Firewall Analyzer looks for either the vpn_user or peer gateway attributes in the logs received from your CheckPoint firewalls to generate VPN reports. All the received logs are stored in Firewall_Analyzer_Home\server\default\archive\ directory. You can browse through those logs to troubleshoot the problem. I am not getting Attack Reports in CheckPoint firewall? Firewall Analyzer looks for the attribute attack in the CheckPoint firewall logs to generate the attack reports. Firewall Analyzer shows the destination site (example: www.yahoo.com) but it is not showing the complete URL (example: www.yahoo.com/index.html)? It looks for the attribute resource in the log. Why do I see zero results for kilobytes transferred in the reports for Check Point firewall? This could be happening because bandwidth information is not being captured in the log file. Ensure that your Check Point firewall has been configured to generate both regular and accounting log files. While regular log files contain information regarding firewall activity, the accounting log file contains the bandwidth and session information. Please refer the Configuring Check Point Firewalls section for help on creating the accounting log file. I am getting only Unknown Events in Event Overview graphs in the dashboard? CheckPoint firewall logs do not have the priority or severity fields. Event Overview graph groups Events based on severity. As there is no severity in check point logs, Firewall Analyzer puts default value as Unknown severity and hence Event Overview shows only Unknown Events. If you drill down that group or by clicking the More link, you can get complete Events. How to fetch rules from files in CheckPoint Firewall? Rule File
Configuration File
Only for Check Point Firewall
Cisco PIX Firewall Reports I am not seeing Traffic reports in Cisco firewalls?
I am not getting VPN reports for Cisco firewalls? We can setup two kind of VPNs in Cisco firewalls as below.
This vpn connection will be established between firewall to firewall. In most of the cases, this connection would have been established before the Firewall Analyzer installation. Also Cisco firewalls do no hint about the traffic that is going through this Site To Site VPN tunnel in the logs. So Firewall Analyzer is not supporting this type of VPN connection now. My Attack Reports displays "No Data Available"? Cisco firewalls have inbuilt Intrusion Detection Systems (IDS) that detects the attacks. Firewall Analyzer supports all attack logs in Cisco firewall devices. All the attacks are identified by the cisco ids from 400000 to 400050. Apart from these logs, Firewall Analyzer also identifies supports IDs like 106016, 106017 etc. So if you find Attack reports empty there is a very valid chance that you have not received any attacks. To verify that you can go to Firewall_Analyzer_Home\server\default\archive\ and search for the above IDs. My Virus Reports are never getting populated? In Cisco firewalls, all the doubtful activities will be identified as attacks and hence you will see all of them in Attack Reports. No Virus logs are given by Cisco Firewalls and hence there are no Virus Reports. You can very well remove the listing of Virus reports through report customization. My Admin Reports displays "No Data Available"? Firewall Analyzer reports login/logout attempts by searching the Cisco firewall logs for message ids like 611101,611102, 611103, 605004, and 605005. Take a look at the logs available at Firewall_Analyzer_Home\server\default\archive\ directory in case of any discrepancy. What is the prerequisite for getting vdom/context Firewall reports for Cisco firewalls? The Cisco Firewall IP address should be DNS resolvable from the Firewall Analyzer. NetScreen Firewall Reports (Syslog) I am not getting any traffic reports. All SENT and RECEIVED values are shown as zero?
The VPN reports for my NetScreen firewalls are not getting populated? Firewall Analyzer searches for action=Tunnel attributes in the NetScreen firewall logs to generate VPN reports.
I am not getting Virus reports for NetScreen firewalls? Firewall Analyzer searches for the attribute Virus in the NetScreen firewall logs to generate Virus reports. Take a look at the log files available under Firewall_Analyzer_Home/server/default/archive/ directory in case of any discrepancy. Other Firewall Reports (Sonicwall, Fortigate, and all other firewalls that support WELF) My reports show No Data Available This means Firewall Analyzer has discovered your firewall and is able to recognize the logs. By default, as soon as you login, Firewall Analyzer shows data from current day's 00:00:00 hrs to current time of the machine where you are running Firewall Analyzer. There is a possibility that the firewall logs timestamp could be different from the Firewall Analyzer's timestamp. So just check Firewall_Analyzer_Home/server/default/archive/ directory to view the firewall logs timestamp. I am not getting any traffic reports? Make sure you have enabled traffic logs and have set your logging level to informational. This is because most of the firewalls generate traffic logs only when logging level is set to informational. The VPN reports for my firewall does not show any data? Firewall Analyzer searches for attributes like vpn= or vpnpolicy= to generate VPN reports. So please verify whether your firewall logs have these attributes. The Virus Reports for my firewall is not getting populated? Firewall Analyzer searches for the attributes like virus= to generate the virus reports. Example logs are given below. The Attack Reports for my firewall is not getting populated? Firewall Analyzer searches for the attributes like attack= or attack_id= to generate attack reports. Example logs are given below. I am not getting complete URLs for the destination sites? Firewall Analyzer combines values of the fields like dst/dstname and arg to form the complete url. Kindly check whether your firewall generates the same in the log files available under Firewall_Analyzer_Home/server/default/archive/ directory. Example logs are given below. Configure Fortigate in High Availability Mode In case of Fortigate Firewalls , device_id is considered as resource name in Firewall Analyzer. In the High Availability mode, eventhough both active and standby Firewalls have the same name, the device_id will be different. So, Firewall Analyzer displays them as two devices. To avoid this, you can configure the device name (devname) of standby Firewall as device_id of active Firewall.
Active Firewall log: <189>date=2011-09-28 time=13:14:58 devname=DSAC456Z4 device_id=FGT80G3419623587 log_id=0021000002 |
- News
- |
- Company
- |
- Customers
- |
- Community
- |
- Newsletter