Logging and Monitoring Flashcards

1
Q

Areas covered by this deck on Logging and Monitoring are:

A

Logging and notifications
Log messages and types
Firebox visibility with WatchGuard Cloud
How to set up Dimension for Firebox logging
How to log to Dimension
Monitoring with Firebox System Manager
Monitoring with Fireware Web UI
How to read Traffic Log messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Fireboxes can send log messages to which types of servers (for managing Fireboxes)?

A

WatchGuard Cloud (serverlike)
Dimension Server
Syslog Server
WatchGuard Log Server (supports fewer reports)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Can Watchguard Servers such as Cloud, Syslog, and WG Log server also generate notifications from monitoring?

A

Yes: WatchGuard Servers also generate log messages and can
send log messages to Dimension or a local file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

WG Log Server and Report Server are not preferred after Fireware v 11.8. What is the reason and what are recommended monitoring servers?

A

The WGLS and RS don’t generate notifications for security services and features added in/after v 11.8 , such as APT Blocker.
To make security services be fully effective, Dimension or WatchGuard Cloud are best choices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the five types of Log Messages Fireboxes send?

A

Traffic - packet filter and proxy policy rules
Alarm - when an event occurs (that may need attention)
Event - when administrator completes tasks, when the device starts or shuts down, and when hardware problems occur
Debug - include information used to help troubleshoot problems - and you can change the level of these log messages
Statistic - information about the performance, including by default external interface performance and VPN bandwidth statistics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where are log messages stored by default?

A

The Firebox can send log messages to WatchGuard Cloud or Dimension in a local PostgreSQL database.
You can also select to use an external PostgreSQL database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the Diagnostic log levels?

A

The available levels, from lowest to highest are:
Off — no diagnostic messages
Error — for serious errors that cause a service or process on the Firebox to terminate, including branch office VPN (BOVPN) errors.
Warning — details abnormal conditions that help explain behavioral process issues, plus the Error level above.
Information — details of successful operation, as well as the information from Error and Warning levels.
Debug — log messages for all log levels. Use only when directed by WatchGuard technical support.
NOTE: By default, the diagnostic log level for all log message types is set to Error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly