Перейти к содержанию

Security | *

Security | ACL | ACL Deny

Variables

NameTypeDescriptionRequired
namestrACL Name
protostrProtocol
src_interfaceinterface_nameSource Interface
src_ipip_addressSource IP
src_portintSource port
src_macmacSource MAC
dst_interfaceinterface_nameDestination Interface
dst_ipip_addressDestination IP
dst_portintDestination port
countintPackets count
flagsstrFlags

Security | ACL | ACL Permit

Variables

NameTypeDescriptionRequired
namestrACL Name
protostrProtocol
src_interfaceinterface_nameSource Interface
src_ipip_addressSource IP
src_portintSource port
src_macmacSource MAC
dst_interfaceinterface_nameDestination Interface
dst_ipip_addressDestination IP
dst_portintDestination port
countintPackets count
flagsstrFlags

Security | Abduct | Cable Abduct

Probable Causes

Multiple access links goes down almost in same time

Recommended Actions

Check electrics and send security team to catch the thief

Related Alarms

Alarm ClassRoleDescription
Security | Abduct | Cable Abduct opening eventdispose

Security | Access | Case Close

Variables

NameTypeDescriptionRequired
namestrName

Related Alarms

Alarm ClassRoleDescription
Security | Access | Case Open closing eventdispose

Security | Access | Case Open

Variables

NameTypeDescriptionRequired
namestrName

Related Alarms

Alarm ClassRoleDescription
Security | Access | Case Open opening eventdispose

Security | Access | Door Close

Variables

NameTypeDescriptionRequired
namestrName

Related Alarms

Alarm ClassRoleDescription
Security | Access | Door Open closing eventdispose

Security | Access | Door Open

Variables

NameTypeDescriptionRequired
namestrName

Related Alarms

Alarm ClassRoleDescription
Security | Access | Door Open opening eventdispose

Security | Accounting | WebVPN | Assigned

Variables

NameTypeDescriptionRequired
groupstrGroup WebVPN
userstrUser
src_ipip_addressUser outside IP
dst_ipipv4_addressUser inside IP
dst_ipv6ipv6_addressUser inside ipv6

Security | Accounting | WebVPN | Disconnected

Symptoms

No specific symptoms

Probable Causes

Session terminated

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
groupstrGroup WebVPN
userstrUsername
ipip_addressIP
typestrSession type
durationintDuration
bytes_xmtintBytes xmt
bytes_rcvintBytes rcv
reasonstrReason

Security | Attack | Attack

Symptoms

Unsolicitized traffic from source

Probable Causes

Virus/Botnet activity or malicious actions

Recommended Actions

Negotiate the source if it is your customer, or ignore

Variables

NameTypeDescriptionRequired
namestrAttack name
interfaceinterface_nameInterface
src_ipip_addressSource IP
src_macmacSource MAC
vlanintVlan ID

Related Alarms

Alarm ClassRoleDescription
Security | Attack | Attack opening eventdispose

Security | Attack | Blat Attack

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP

Related Alarms

Alarm ClassRoleDescription
Security | Attack | Blat Attack opening eventdispose

Security | Attack | IP Spoofing

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP
src_macmacSource MAC

Related Alarms

Alarm ClassRoleDescription
Security | Attack | IP Spoofing opening eventdispose

Security | Attack | Land Attack

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP

Related Alarms

Alarm ClassRoleDescription
Security | Attack | Land Attack opening eventdispose

Security | Attack | Ping Of Death

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP
src_macmacSource MAC

Related Alarms

Alarm ClassRoleDescription
Security | Attack | Ping Of Death opening eventdispose

Security | Attack | Smurf Attack

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP

Related Alarms

Alarm ClassRoleDescription
Security | Attack | Smurf Attack opening eventdispose

Security | Attack | TCP SYNFIN Scan

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP

Related Alarms

Alarm ClassRoleDescription
Security | Attack | TCP SYNFIN Scan opening eventdispose

Security | Attack | Teardrop Attack

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface
src_ipip_addressSource IP
src_macmacSource MAC

Related Alarms

Alarm ClassRoleDescription
Security | Attack | Teardrop Attack opening eventdispose

Security | Audit | Clearing Counters

Variables

NameTypeDescriptionRequired
interfaceinterface_nameInterface name
userstrUser
ipip_addressUser IP

Security | Audit | Command

Symptoms

No specific symptoms

Probable Causes

Command executed by user logged by audit system

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser IP
commandstrCommand

Security | Audit | Cron

Symptoms

No specific symptoms

Probable Causes

Command executed by cron

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
commandstrCommand

Security | Authentication | 802.1x failed

Variables

NameTypeDescriptionRequired
userstruser name

Security | Authentication | Authentication Failed

Symptoms

No specific symptoms

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser address

Security | Authentication | Login

Symptoms

No specific symptoms

Probable Causes

User successfully logged in

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser address

Security | Authentication | Login Failed

Symptoms

No specific symptoms

Probable Causes

User failed to log in. Username or password mismatch

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser address

Security | Authentication | Logout

Symptoms

No specific symptoms

Probable Causes

User successfully logged out. Session terminated

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser address

Security | Authentication | Privilege Level Change Fail

Symptoms

No specific symptoms

Probable Causes

User privilege level changed

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser address
from_privstrOld privilegies
to_privstrCurrent privilegies

Security | Authentication | Privilege Level Changed

Symptoms

No specific symptoms

Probable Causes

User privilege level changed

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
userstrUser
ipip_addressUser address
from_privstrOld privilegies
to_privstrCurrent privilegies

Security | Authentication | RADIUS server failed

Variables

NameTypeDescriptionRequired
ipip_addressRADIUS server address

Related Alarms

Alarm ClassRoleDescription
Security | Authentication | RADIUS server failed opening eventdispose

Security | Authentication | RADIUS server recovered

Variables

NameTypeDescriptionRequired
ipip_addressRADIUS server address

Related Alarms

Alarm ClassRoleDescription
Security | Authentication | RADIUS server failed closing eventdispose

Security | Authentication | Rejected

Symptoms

No specific symptoms

Probable Causes

User successfully logged out. Session terminated

Recommended Actions

No reaction needed

Variables

NameTypeDescriptionRequired
reasonstrReason
serverip_addressServer
userstrUser
src_ipip_addressOutside user ip

Security | Authentication | SNMP Authentication Failure

Symptoms

NOC, NMS and monitoring systems cannot interact with the box over SNMP protocol

Probable Causes

SNMP server is misconfigured, community mismatch, misconfigured ACL or brute-force attack in progress

Recommended Actions

Check SNMP configuration

Variables

NameTypeDescriptionRequired
ipip_addressRequest source address
communitystrRequest SNMP community

Security | Authentication | TACACS+ server failed

Variables

NameTypeDescriptionRequired
ipip_addressTACACS+ server address

Related Alarms

Alarm ClassRoleDescription
Security | Authentication | TACACS+ server failed opening eventdispose

Security | Authentication | TACACS+ server recovered

Variables

NameTypeDescriptionRequired
ipip_addressTACACS+ server address

Related Alarms

Alarm ClassRoleDescription
Security | Authentication | TACACS+ server failed closing eventdispose