Logging and Monitoring Flashcards
Areas covered by this deck on Logging and Monitoring are:
Logging and notifications
Log messages and types
Firebox visibility with WatchGuard Cloud
How to set up Dimension for Firebox logging
How to log to Dimension
Monitoring with Firebox System Manager
Monitoring with Fireware Web UI
How to read Traffic Log messages
Fireboxes can send log messages to which types of servers (for managing Fireboxes)?
WatchGuard Cloud (serverlike)
Dimension Server
Syslog Server
WatchGuard Log Server (supports fewer reports)
Can Watchguard Servers such as Cloud, Syslog, and WG Log server also generate notifications from monitoring?
Yes: WatchGuard Servers also generate log messages and can
send log messages to Dimension or a local file.
WG Log Server and Report Server are not preferred after Fireware v 11.8. What is the reason and what are recommended monitoring servers?
The WGLS and RS don’t generate notifications for security services and features added in/after v 11.8 , such as APT Blocker.
To make security services be fully effective, Dimension or WatchGuard Cloud are best choices.
What are the five types of Log Messages Fireboxes send?
Traffic - packet filter and proxy policy rules
Alarm - when an event occurs (that may need attention)
Event - when administrator completes tasks, when the device starts or shuts down, and when hardware problems occur
Debug - include information used to help troubleshoot problems - and you can change the level of these log messages
Statistic - information about the performance, including by default external interface performance and VPN bandwidth statistics
Where are log messages stored by default?
The Firebox can send log messages to WatchGuard Cloud or Dimension in a local PostgreSQL database.
You can also select to use an external PostgreSQL database.
What are the Diagnostic log levels?
The available levels, from lowest to highest are:
Off — no diagnostic messages
Error — for serious errors that cause a service or process on the Firebox to terminate, including branch office VPN (BOVPN) errors.
Warning — details abnormal conditions that help explain behavioral process issues, plus the Error level above.
Information — details of successful operation, as well as the information from Error and Warning levels.
Debug — log messages for all log levels. Use only when directed by WatchGuard technical support.
NOTE: By default, the diagnostic log level for all log message types is set to Error