Firewall Analyzer - Inventory - Devices


 

The Devices tab shows the devices that have been added to the firewall Analyzer. It also shows the activity status of the added firewall devices. Apart from this it shows the vendor name, the type and status of the firewall device. By default, the devices are listed in table view, click on the view menu to change to list view. The Devices can also be searched for using the search menu.

Inventory devices in Firewall Analyzer: Device snapshot page

The following data is shown in the device tab.

NameName of the device.
LicenseIf the licence is managed or unmanaged.
IP AddressThe IP address in which the device is configured. 
TypeThe type of network security device.
VendorThe type of vendor.
Uplink SpeedThe Uplink speed of the device.
Downlink SpeedThe downlink speed of the device.
Intranet Setting.Provides information on if or not the Intranet is configured.
SNMPProvides information on If or not the SNMP is configured.

On clicking on any one of the devices, a short summary for that live traffic is shown. 

Create a new alarm profile by clicking on the "Create Alarm Profile" menu. 

Create a new report profile by clicking on the "Create Report Profile" menu.  

Delete the device using the "delete" button. 

The menu button (Three dots) is found on the top right corner. On clicking the same you get the following options:

  1. Edit Devices - Where you can edit display name, uplink speed and downlink speed
  2. Unmanage - Unmanage/manage a firewall.
  3. Device rule - Edit the device rule.
  4. SNMP Settings - Edit the SNMP Settings.
  5. Intranet settings - Edit the intranet settings.
  6. Exclude Host -  Exclude a host
  7. Availability Alert - Create an availability alert.

The short summary gives details on the traffic going through that device, both Traffic In and Traffic Out. On expanding the short summary, you get access to in depth reports which has the following graphs.

1. Summary- This provides the summary of the firewall device.

By default, the Uplink and Downlink speed will be shown as 1 Mbps, the same can be edited by using menu icon. Click on Edit Devices - Where you can edit the uplink speed and downlink speed. 

Inventory devices in Firewall Analyzer: Summary

Device rule - Edit the device rule.

SNMP Settings - Edit the SNMP Settings.

Intranet settings - Edit the intranet settings.

Exclude Host -  Exclude a host

2. Bandwidth- The traffic in and out of the firewall devices.

Inventory devices in Firewall Analyzer: Bandwidth

On clicking on the bandwidth report, a detailed bandwidth report "Inbound Traffic Conversations" is shown with the following fields.

SourceThe source IP
UserUser triggering the inbound traffic
DestinationThe destination IP
TimeTime stamp of when the traffic originated
Rule numberThe rule used to access the IP
ProtocolThe protocol used to access the IP
SeverityThe severity of the inbound traffic
DurationThe duration of the traffic
BytesThe number of bytes consumed

3. Top 10- Gives the Top 10 host IP, Destination IP, Protocol groups, Internal server, external sites and conversations.

Inventory devices in Firewall Analyzer: Top 10

On clicking the individual host, you get a further drill down on the individual host.

  1. Top Protocol Groups
  2. Top Destinations
  3. Top URLs Allowed 
  4. Top URLs Blocked 
  5. Rules Triggered

On clicking the individual destination, you get a further drill down on the individual destination.

  1. Top Hosts
  2. Top Protocol Groups
  3. Top conversations 
  4. Top URLs
  5. Top URLs Blocked

On clicking the individual protocol group, you get a further drill down on the individual protocol group.

  1. Top Protocols
  2. Top Hosts
  3. Top Destinations
  4. Top Conversations
  5. Traffic Distribution - Working Hours
  6. Traffic Distribution - Non Working Hour

On clicking the individual external site, you get a further drill down on the individual external site.

  1. Top Hosts
  2. Top Protocol Groups
  3. Top conversations 
  4. Top URLs
  5. Top URLs Blocked

4. Sites- Gives the list and traffic of allowed sites accessed and denied sites attempted.

Inventory devices in Firewall Analyzer: Sites

5. Apps- The applications which run via the devices are shown in the graph. We also show the application based on category.

Inventory devices in Firewall Analyzer: Apps

On clicking on the individual application we get a drill down on the following

  1. Top Hosts
  2. Top Protocols
  3. Top Users 
  4. Top Conversations

On clicking on the individual application category we get a drill down on the following

  1. Top Applications
  2. Top Hosts
  3. Top Users 
  4. Top Conversations

 

Refer the Firewall Analyzer Supported Devices page for the list of devices for which Application Report is supported.

 

 

6. Rules- Gives the usage trend of Firewall rules, top allowed rules and top denied rules triggered.

Inventory devices in Firewall Analyzer: Rules

On clicking on the individual top allowed and denied rules, we get a drill down on the following:

  1. Rule Usage Trend
  2. Rule Usage
  3. Rule Description

7. Security- Gives an overview of security stats, top attacks, top virus attacks, top denied host IP, top denied destination IP and denied user logon.

Inventory devices in Firewall Analyzer: Security

On clicking on the individual Attack and Virus we get a drill down on the following

HostThe Host IP of the attack/virus
DestinationThe destination IP of the attack/virus
ProtocolThe protocol used to attack
SeverityThe severity of the attack/virus
HitsThe number of hits
SubtypeThe subtype of the attack/virus
StatusThe Status of the attack/virus

8.VPN- The VPNs connecting via the device.

Inventory devices in Firewall Analyzer: VPN

Thank you for your feedback!

Was this content helpful?

We are sorry. Help us improve this page.

How can we improve this page?
Do you need assistance with this topic?
By clicking "Submit", you agree to processing of personal data according to the Privacy Policy.
A single platter for comprehensive Network Security Device Management