Adash 3600-MPX Uživatelská příručka

Procházejte online nebo si stáhněte Uživatelská příručka pro Software Adash 3600-MPX. Adash 3600-MPX User guide Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 183
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - User Guide

Reconnex inSight / iGuard 7.0.0.4 User Guide January 18, 2008 Reconnex Corp

Strany 2 - Copyright

Reconnex Corporation 2 Release 7.0.0.4 The inSight appliance takes over iGuard tasks like customizing policies and assigning privileges to

Strany 3 - Contents

Reconnex Corporation 92 Release 7.0.0.4 Delete a Policy There are two ways of deleting a policy. Note: You can delete a policy only if you

Strany 4

iGuard/inSight User Guide Release 7.0.0.4 93 If you are not seeing the machine you need to publish a policy to, you must first add that de

Strany 5

Reconnex Corporation 94 Release 7.0.0.4 3. Type in the new name. When you start typing, a Save As button will appear. Before saving, mak

Strany 6

iGuard/inSight User Guide Release 7.0.0.4 95 3. Fill in a new name and description. A Save As button will be added when you start typing

Strany 7

Reconnex Corporation 96 Release 7.0.0.4 3. Save. The policy list that is launched will show the change in ownership in the Owner column. N

Strany 8

iGuard/inSight User Guide Release 7.0.0.4 97 Note: Rule state is especially significant because you cannot run more than 256 active rules.

Strany 9 - The Reconnex Solution

Reconnex Corporation 98 Release 7.0.0.4 3. Save Search. 4. Give the new rule a name. Important: The characters * % @ + # ? , ' &qu

Strany 10 - Features of Release 7.0.0.4

iGuard/inSight User Guide Release 7.0.0.4 99 1. Go to the Policies tab. 2. Click on a policy. 3. Click on a rule you want to tune, or Ad

Strany 11 - Reconnex Architecture

Reconnex Corporation 100 Release 7.0.0.4 In this case, you are excluding the Director of Human Resources, anyone on the Human Resources a

Strany 12 - Use Cases

iGuard/inSight User Guide Release 7.0.0.4 101 2. Click on the name of the policy to open it. 3. Click on the name of the rule. 4. Select

Strany 13 - Find Covert Email

iGuard/inSight User Guide Release 7.0.0.4 3 Reconnex Architecture Reconnex architecture supports essential 32- and 64-bit platforms which i

Strany 14

Reconnex Corporation 102 Release 7.0.0.4 6. If you have a pre-configured Prevent setup, you may capture identities of Manager, Reviewer,

Strany 15 - Find Data Leaked in the Past

iGuard/inSight User Guide Release 7.0.0.4 103 15. If you have a pre-configured Prevent setup, you may extend notification by assigning a

Strany 16

Reconnex Corporation 104 Release 7.0.0.4 6. Click on the Action you want to apply. 7. Save. The new action rule is immediately added unde

Strany 17 - Find Encrypted Traffic

iGuard/inSight User Guide Release 7.0.0.4 105 4. Confirm or cancel the deletion. What is a Concept? Concepts are pattern-matching devices

Strany 18

Reconnex Corporation 106 Release 7.0.0.4 Consumption CREDIT-REPORT Credit report information identifying agencies DATE-OF-BIRTH Terms perta

Strany 19

iGuard/inSight User Guide Release 7.0.0.4 107 JCB Non-numeric terms pertaining to JCB credit card expression LAST-NAME Terms pertaining to

Strany 20

Reconnex Corporation 108 Release 7.0.0.4 SECURITY-AGENCIES Terms that identify mention of security agency domains, e.g. – nsa.gov, cia.gov,

Strany 21

iGuard/inSight User Guide Release 7.0.0.4 109 6. Upload expressions (optional). Tip: The Upload Expressions function will save you a lot

Strany 22

Reconnex Corporation 110 Release 7.0.0.4 Concept Conditions Applying conditions to concepts you have constructed help you to exert greater

Strany 23

iGuard/inSight User Guide Release 7.0.0.4 111 8. Define the number of bytes from the beginning of the captured object in which you want i

Strany 24

Reconnex Corporation 4 Release 7.0.0.4 Use Cases The standard policies shipped with iGuard contain rules that automatically capture many of

Strany 25

Reconnex Corporation 112 Release 7.0.0.4 \w any alphanumeric \c or \d \W not alphanumeric ^\w \s any space [\ \f \n \r \t] \S not any s

Strany 26

iGuard/inSight User Guide Release 7.0.0.4 113 5. Enter the hostname as it will be found in the header. 6. Save. 7. Verify that the new

Strany 27

Reconnex Corporation 114 Release 7.0.0.4 Now you can add a new element to use your BLOGPOST search in combination with a query for Microso

Strany 28

iGuard/inSight User Guide Release 7.0.0.4 115 To view any incidents that are generated by the rule, go to Monitor and Group by Rule. When y

Strany 29

Reconnex Corporation 116 Release 7.0.0.4 Tip: Click on the template name to see what it contains. Create a Template Searching or creating

Strany 30

iGuard/inSight User Guide Release 7.0.0.4 117 2. Click on Templates. 3. Click on Create New Template. 4. Name and describe the template

Strany 31

Reconnex Corporation 118 Release 7.0.0.4 Now that your template is defined, you can pick it up from the "?" palette launched fr

Strany 32

iGuard/inSight User Guide Release 7.0.0.4 119 Managing the System You can use the System tab on your inSight or iGuard to monitor the healt

Strany 33 - Using the System

Reconnex Corporation 120 Release 7.0.0.4 When iGuard interfaces are silent, no data is flowing through the capture ports. If this is being

Strany 34 - Custom Dashboard Viewing

iGuard/inSight User Guide Release 7.0.0.4 121 7. Check one or more boxes from the palette to define the alert subcategory. 8. Click on

Strany 35 - Incident Viewing Options

iGuard/inSight User Guide Release 7.0.0.4 5 Find traffic to and from foreign nationals Loss of intellectual property to emerging markets ha

Strany 36 - Get Incident Details

Reconnex Corporation 122 Release 7.0.0.4 5. Save. 6. Verify that the alert notification is added to the list of recipients that is launc

Strany 37

iGuard/inSight User Guide Release 7.0.0.4 123 1. Create users and user groups. 2. Add an LDAP server (optional). 3. Create LDAP users (o

Strany 38

Reconnex Corporation 124 Release 7.0.0.4 These role-based user groups are supplied only as a suggested uniform framework for multiple user

Strany 39 - Incident Examples

iGuard/inSight User Guide Release 7.0.0.4 125 8. Click Add to the Current Members pane. 9. Select Update. 10. Verify that the new grou

Strany 40

Reconnex Corporation 126 Release 7.0.0.4 Role-Based Multi-User Access Role-based multi-user access allows assignation of varying levels of

Strany 41 - Delete Incidents

iGuard/inSight User Guide Release 7.0.0.4 127 5. Click the down arrow to display the permissions list. 6. Check or clear the boxes corres

Strany 42 - Filter by Time

Reconnex Corporation 128 Release 7.0.0.4 6. Update. Tip: If the user doesn't fit logically into the available groups, you must add

Strany 43

iGuard/inSight User Guide Release 7.0.0.4 129 Create a Failover Account If the link between the inSight Console and its iGuards is broken,

Strany 44 - Filter by Group

Reconnex Corporation 130 Release 7.0.0.4 2. Select the Detail link opposite your username in the navigation bar. 3. Note your Current Gro

Strany 45 - Filtering Examples

iGuard/inSight User Guide Release 7.0.0.4 131 Any of the following actions may be cited on the User Audit Log page. Recognized User Activi

Strany 46

Reconnex Corporation 6 Release 7.0.0.4 3. Select the equals condition. 4. Click on the "?" to launch the values palette. 5. Se

Strany 47

Reconnex Corporation 132 Release 7.0.0.4 15. Modify DHCP server 16. Update DHCP server 17. Delete DHCP server 18. View Capture filter l

Strany 48 - Save a Report

iGuard/inSight User Guide Release 7.0.0.4 133 50. Delete user group 51. View group permissions 52. View group task permissions 53. View

Strany 49 - My Reports

Reconnex Corporation 134 Release 7.0.0.4 85. Schedule a policy 86. De-schedule a policy 87. View export schedule search page 88. Downl

Strany 50 - Report Examples

iGuard/inSight User Guide Release 7.0.0.4 135 120. View incident annotations 121. View incident cases 122. Modify case 123. Mark incident a

Strany 51 - Export a CSV Report

Reconnex Corporation 136 Release 7.0.0.4 155. View risk summary 156. View network summary 157. View case summary 158. View case list Audit

Strany 52 - Export a PDF Report

iGuard/inSight User Guide Release 7.0.0.4 137 keep them up-to-date. Audit Log Filtering If you are an inSight administrator, you will want

Strany 53

Reconnex Corporation 138 Release 7.0.0.4 Note: If you want to add more than one item, separate them with a comma (no space). 8. When you

Strany 54

iGuard/inSight User Guide Release 7.0.0.4 139 5. Update. Setup Wizard Method 1. Go to System > System Administration. 2. On the list

Strany 55

Reconnex Corporation 140 Release 7.0.0.4 What are Capture Filters? There are two capture filter types. They are generally used to define si

Strany 56 - Copy Report Views to Users

iGuard/inSight User Guide Release 7.0.0.4 141 Drop Element excludes all data associated with an element. For example, your network may hav

Strany 57 - Delete a Report

iGuard/inSight User Guide Release 7.0.0.4 7 12. Select Group by Detail from the dashboard header. This will give you a graphical picture

Strany 58

Reconnex Corporation 142 Release 7.0.0.4 This filter excludes images in BMP and GIF formats. Ignore HTTP Gzip Responses This filter exclu

Strany 59 - Create a Case

iGuard/inSight User Guide Release 7.0.0.4 143 This filter excludes Server Message Block/NETBIOS traffic. Ignore SSH Traffic This filter e

Strany 60 - Assign a Case

Reconnex Corporation 144 Release 7.0.0.4 8. Define the protocol. In this example, you are eliminating video file types that are being tr

Strany 61

iGuard/inSight User Guide Release 7.0.0.4 145 Create a Network Capture Filter Designing a network capture filter requires experimentation,

Strany 62 - Add to an Existing Case

Reconnex Corporation 146 Release 7.0.0.4 8. Save. The list of filters will be launched. 9. Verify that the new filter has been added to

Strany 63

iGuard/inSight User Guide Release 7.0.0.4 147 10. Reprioritize the order in which the filters will run. Remember, the Base filter must b

Strany 64

Reconnex Corporation 148 Release 7.0.0.4 Filters that define larger amounts of traffic should be placed at or near the top of the list. For

Strany 65 - Change Resolution of a Case

iGuard/inSight User Guide Release 7.0.0.4 149 3. Select the filter you want to activate. 4. Verify that the filter has been added to the

Strany 66 - Before Searching

Reconnex Corporation 150 Release 7.0.0.4 Modify a Capture Filter To modify a capture filter, just click on its name and edit its properties

Strany 67 - Command Line Identifiers

iGuard/inSight User Guide Release 7.0.0.4 151 Conversely, transport of large-sized files may indicate inappropriate usage of network resou

Strany 68

Reconnex Corporation 8 Release 7.0.0.4 4. If you have an idea if when the leak may have occurred, select a time period. 5. Search. Your

Strany 69 - South America

Reconnex Corporation 152 Release 7.0.0.4 To identify such a problem, it would only be necessary to store the metadata indicating that large

Strany 70

iGuard/inSight User Guide Release 7.0.0.4 153 8. Verify that the new filter is listed in the window that is launched. CIDR Classless Inte

Strany 71 - Middle-East and Asia

Reconnex Corporation 154 Release 7.0.0.4 3. Indicate the device on which you want the filter deployed. If you want to decide later, you c

Strany 72 - Asia-Pacific

iGuard/inSight User Guide Release 7.0.0.4 155 10. Save. 11. Verify that the new filters are listed in the window that is launched. 12.

Strany 73 - Africa

Reconnex Corporation 156 Release 7.0.0.4 Advanced Utilities You can run Linux, SQL or RFS Reconnex File Systemcommands in real time by goin

Strany 74

iGuard/inSight User Guide Release 7.0.0.4 157 Statistic Description Life Seconds since the flow was created Stale Seconds since the last pa

Strany 75 - Europe

Reconnex Corporation 158 Release 7.0.0.4 2. Click on the name of a log to launch it. 3. Copy and paste the contents of a log into a text

Strany 76 - Capture Chat Sessions

iGuard/inSight User Guide Release 7.0.0.4 159 Managing Disk Space The Reconnex File System (RFS) divides the iGuard disk (depending on your

Strany 77 - Search by Concept

Reconnex Corporation 160 Release 7.0.0.4 WARNING: Changing a wiping policy can have unpredictable results. Before doing this, consult Recon

Strany 78 - Search by Content Type

iGuard/inSight User Guide Release 7.0.0.4 161 4. On your Active Directory Server desktop, go to Start > Administrative Tools > Activ

Strany 79 - Formats

iGuard/inSight User Guide Release 7.0.0.4 9 Digest Search To find a specific document, you can generate a compact digital signature from th

Strany 80 - Search by Email Address

Reconnex Corporation 162 Release 7.0.0.4 3. Add the server name or IP address. 4. Add the server port number. 5. Add the timeout inter

Strany 81 - Search by Filename

iGuard/inSight User Guide Release 7.0.0.4 163 15. To edit the settings, select Detail. The Server Information dialog box will launch. It

Strany 82 - Search by Keywords

Reconnex Corporation 164 Release 7.0.0.4 You may want to narrow that query by using metacharacters combined with text. This will retrieve

Strany 83 - Find the exact phrase

iGuard/inSight User Guide Release 7.0.0.4 165 4. Select one or more groups for the new user(s) and Add. Note: User permissions are assig

Strany 84

Reconnex Corporation 166 Release 7.0.0.4 Managing Devices The inSight Console controls all other Reconnex devices on your network. This inc

Strany 85 - Search by Location

iGuard/inSight User Guide Release 7.0.0.4 167 Note: It takes a few minutes to register the device. The Registration icon shows that regis

Strany 86 - Search by Port Number

Reconnex Corporation 168 Release 7.0.0.4 The Utilities page will be launched. 3. Scroll down to the bottom of the page. 5. Select De-re

Strany 87 - Search by Protocol

iGuard/inSight User Guide Release 7.0.0.4 169 Contact Technical Support For troubleshooting assistance, you can contact Reconnex Technical

Strany 88 - Search by URL

Reconnex Corporation 170 Release 7.0.0.4 Power Redundancy To ensure redundancy on the 1650 and 3650 appliances, both power supplies must b

Strany 89 - Search for Images

iGuard/inSight User Guide Release 7.0.0.4 171 Mechanical Loading Mounting of the equipment in the rack should be such that a hazardous cond

Strany 90 - Search for Fleshtone Images

Reconnex Corporation 10 Release 7.0.0.4 5. Click on the "?" to launch the Values palette. 6. Select Crypto from the Protocol li

Strany 92 - Word Limitations

User Guide for inSight/iGuard Release 7.0.0.4 171 Index A Account Information, 126 Action Rules create, 99 define, 99 delete, 102 modify, 101 A

Strany 93

Reconnex Corporation 172 Release 7.0.0.4 I iGuard Architecture, 3 features, 1 Reconnex Solution, 1 Incidents customize report, 26 delete, 33 Det

Strany 94 - Use Keyword Search Shorthand

User Guide for inSight/iGuard Release 7.0.0.4 173 by user ID, 79 Command Line, 57 compound queries, 67 country codes, 60 distributed, 67 filters

Strany 95 - Use Logical Operators

iGuard/inSight User Guide Release 7.0.0.4 11 Find FTP Traffic Containing Source Code If you have an employee who is leaving the company, y

Strany 96 - Regulatory Policies

Reconnex Corporation ii Release 7.0.0.4 Copyright ©2008 by Reconnex Corporation. All rights reserved. Reconnex™ is the trademark of Reconnex Corpo

Strany 97 - Activation and Inheritance

Reconnex Corporation 12 Release 7.0.0.4 You can narrow the search if you know what kind of compression may have been used on the file(s).

Strany 98 - Create a Policy

iGuard/inSight User Guide Release 7.0.0.4 13 FTP is commonly used to transmit large files, but other transport protocols can be selected f

Strany 99 - Edit a Policy

Reconnex Corporation 14 Release 7.0.0.4 Find Postings to Social Networking Sites Employees sometimes post personal information to popular o

Strany 100 - Publish a Policy

iGuard/inSight User Guide Release 7.0.0.4 15 NOTE: You can just type the concept into the Value field if you prefer. 7. Apply. 8. Search

Strany 101 - Rename a Policy

Reconnex Corporation 16 Release 7.0.0.4 done using Source and Destination IP addresses, whichhelp you to identify where your traffic is com

Strany 102 - Use a Policy as a Template

iGuard/inSight User Guide Release 7.0.0.4 17 When you find related results, you can filter them to reveal additional patterns and give you

Strany 103 - Change Ownership of a Policy

Reconnex Corporation 18 Release 7.0.0.4 Find Traffic to Gambling or Adult-Oriented Sites Use of the Internet in the workplace has the poten

Strany 104 - Rule-Based Activation

iGuard/inSight User Guide Release 7.0.0.4 19 Note: If you select more than one concept, a logical OR condition is implemented. This is ind

Strany 105 - Create a Rule

Reconnex Corporation 20 Release 7.0.0.4 Find Transmission of Financial Information Searching using iGuard's standard concepts is a qu

Strany 106 - Tune a Rule

iGuard/inSight User Guide Release 7.0.0.4 21 These concepts contain words and phrases that identify a broad range of financial content. Yo

Strany 107 - Example

iGuard/inSight User Guide Release 7.0.0.4 iii Contents The Reconnex Solution ...

Strany 108 - Delete a Rule

Reconnex Corporation 22 Release 7.0.0.4 Investigate a User's Online Activity You may need to monitor online activity for an employee

Strany 109 - Create an Action Rule

iGuard/inSight User Guide Release 7.0.0.4 23 . 6. Click Search. You may prefer to target the search for specific elements by using a more

Strany 110

Reconnex Corporation 24 Release 7.0.0.4 But when you get the results of the search you are using to create the rule, you notice that your F

Strany 111 - Apply an Action Rule

iGuard/inSight User Guide Release 7.0.0.4 25 Using the System If you are using an inSight Console, you are the central management point for

Strany 112 - Delete an Action Rule

Reconnex Corporation 26 Release 7.0.0.4 Custom Dashboard Viewing You can rearrange the columns of the dashboard to give you the informatio

Strany 113 - Standard Concepts

iGuard/inSight User Guide Release 7.0.0.4 27 Note: The Details column is crucial if you want to drill down into your results to access the

Strany 114

Reconnex Corporation 28 Release 7.0.0.4 Get Incident Details When you open an incident, you can drill down into the item displayed to get m

Strany 115

iGuard/inSight User Guide Release 7.0.0.4 29 3. If there is another link within that document, click it. The last link you are able to se

Strany 116 - Create a Concept

Reconnex Corporation 30 Release 7.0.0.4 5. Click on the Concepts tab above the Incident Details. If a concept was used to flag an incide

Strany 117

iGuard/inSight User Guide Release 7.0.0.4 31 Sort Incidents Use the Actions menu to sort any incident or group of incidents into a configur

Strany 118 - Concept Conditions

Reconnex Corporation iv Release 7.0.0.4 Managing Cases ...

Strany 119 - Regular Expression Syntax

Reconnex Corporation 32 Release 7.0.0.4 Find Transmissions between Users 1. Enter DestinationIP equals and enter an IP address. 2. Filte

Strany 120 - Create a Network Concept

iGuard/inSight User Guide Release 7.0.0.4 33 Find Office Document Violations 1. Select Content equals from the first two drop-down menus.

Strany 121

Reconnex Corporation 34 Release 7.0.0.4 Alternatively, you can mark them as false positives or mark for deletion later. Filter by Time B

Strany 122

iGuard/inSight User Guide Release 7.0.0.4 35 Tip: If you are not getting results from a query, try resetting your timestamp filter. Besid

Strany 123 - Standard Templates

Reconnex Corporation 36 Release 7.0.0.4 You can combine timestamp settings with Group by... attributes to expand your options. Filter by G

Strany 124 - Create a Template

iGuard/inSight User Guide Release 7.0.0.4 37 This example shows that the Content grouping has been focused on Filename and Protocol, produ

Strany 125

Reconnex Corporation 38 Release 7.0.0.4 Now that you see these violations listed, you may want to find out additional information - such a

Strany 126 - Delete a Template

iGuard/inSight User Guide Release 7.0.0.4 39 In this example, the user typed in "yahoo.com" to ask the system if any of the numb

Strany 127 - Managing the System

Reconnex Corporation 40 Release 7.0.0.4 Save a Report When you save a report, you are either exporting it to save its content or storing th

Strany 128 - Filter Alerts

iGuard/inSight User Guide Release 7.0.0.4 41 My Reports The reports listed under Monitor > My Reports may have been scheduled for you, o

Strany 129 - Set Up Alert Notification

iGuard/inSight User Guide Release 7.0.0.4 v Use Logical Operators ...

Strany 130 - Manage Users and User Groups

Reconnex Corporation 42 Release 7.0.0.4 Just check the box of the report you want to share and check the names of the users on your team wh

Strany 131 - Preconfigured User Groups

iGuard/inSight User Guide Release 7.0.0.4 43 3. Add a new filter by clicking on the green plus sign. 4. Enter Policy and equals in the f

Strany 132 - Add a User Group

Reconnex Corporation 44 Release 7.0.0.4 4. Pull down the File menu and print, save the page, import or send a link to it. Once you have c

Strany 133 - Assign Permissions

iGuard/inSight User Guide Release 7.0.0.4 45 3. Update. 4. Select Report Options. 5. Select Export as PDF from the menu. Note: By def

Strany 134 - Tasks Permissions

Reconnex Corporation 46 Release 7.0.0.4 Your company information appears at the bottom of the report.

Strany 135 - Policy Permissions

iGuard/inSight User Guide Release 7.0.0.4 47 6. Save a copy, print, zoom, or process your report using any of the other Adobe toolbar ico

Strany 136 - Change Password or Profile

Reconnex Corporation 48 Release 7.0.0.4 3. Enter the sender and recipient email addresses. For multiple addresses, use a comma with no sp

Strany 137 - Find Permissions

iGuard/inSight User Guide Release 7.0.0.4 49 Just check the box of the report you want to share and check the names of the users on your t

Strany 138 - Audit Log Actions

Reconnex Corporation 50 Release 7.0.0.4 Create a Case from the Incident List 1. To create a case from the Incident List, just select the i

Strany 139 - Recognized User Activities

iGuard/inSight User Guide Release 7.0.0.4 51 After you Apply the case, the Case List launches, showing you that the case has been added to

Strany 140

Reconnex Corporation vi Release 7.0.0.4 System Monitor ...

Strany 141

Reconnex Corporation 52 Release 7.0.0.4 3. Apply. After you Apply the case, the Case List launches, showing you that the case has been ad

Strany 142

iGuard/inSight User Guide Release 7.0.0.4 53 4. Enter Case Details. 5. Apply. The Case List will launch, displaying the new case. Export

Strany 143

Reconnex Corporation 54 Release 7.0.0.4 Note: Processing time depends on the size of the file. If you have to wait for completion of the e

Strany 144 - Audit Log Editing

iGuard/inSight User Guide Release 7.0.0.4 55 Then you notice that two American Express numbers were located by another regulatory policy,

Strany 145 - Audit Log Filtering

Reconnex Corporation 56 Release 7.0.0.4 The Case Details window will launch under the case to which the incident has been assigned. 5. U

Strany 146 - System Administration

iGuard/inSight User Guide Release 7.0.0.4 57 Change Owner of a Case 1. Go to the Case tab. 2. Select Details for the case you want to mod

Strany 147 - Setup Wizard

Reconnex Corporation 58 Release 7.0.0.4 4. Select the new resolution. 5. Apply. Change Status of a Case 1. Go to the Case tab. 2. Sele

Strany 148 - Capture Filter Actions

iGuard/inSight User Guide Release 7.0.0.4 59 Command line identifiers can be used alone or as part of a complex query. Example: Find Wor

Strany 149

Reconnex Corporation 60 Release 7.0.0.4 Protocol Option proto: Search by protocol Example On the Basic Search > Custom line, enter the

Strany 150

iGuard/inSight User Guide Release 7.0.0.4 61 concept: Search by concept Example On the Basic Search > Custom line, enter the concept ide

Strany 151

iGuard/inSight User Guide Release 7.0.0.4 vii View Objects ...

Strany 152

Reconnex Corporation 62 Release 7.0.0.4 Central America and the Caribbean Anguilla AI Antigua and Barbuda AG Aruba AW Bahamas BS Barbados

Strany 153

iGuard/inSight User Guide Release 7.0.0.4 63 Middle-East and Asia Afghanistan AF Armenia AM Azerbaijan AZ Bahrain BH Bangladesh BD Bhutan B

Strany 154

Reconnex Corporation 64 Release 7.0.0.4 Palestinian Territory PS Philippines PH Quatar QA Saudi Arabia SA Singapore SG Sri Lanka LK Syrian

Strany 155 - Reprioritize Capture Filters

iGuard/inSight User Guide Release 7.0.0.4 65 Norfolk Island NF Northern Mariana Islands MP Palau PW Papua New Guinea PG Samoa WS Solomon Is

Strany 156 - Activate a Capture Filter

Reconnex Corporation 66 Release 7.0.0.4 Ghana GH Guinea GN Guinea_Bissau GW Kenya KE Lesotho LS Liberia LR Madagascar MG Malawi MW Mali ML

Strany 157 - Deploy Capture Filters

iGuard/inSight User Guide Release 7.0.0.4 67 Antarctica Antarctica AQ Bouvet Island BV Heard Island and McDonald Islands HM Europe Albani

Strany 158 - Filter Out Files by Size

Reconnex Corporation 68 Release 7.0.0.4 Malta MT Moldavia MD Monaco MC Netherlands NL Norway NO Poland PL Portugal PT Romania RO Russian

Strany 159

iGuard/inSight User Guide Release 7.0.0.4 69 Yahoo version 8.1.0.421 • AOL version 4.7.2517 • MSN/Windows Live messenger 8.1.0178 •

Strany 160

Reconnex Corporation 70 Release 7.0.0.4 Alternatively, you can use the expression condition to type in the name of a standard or custom

Strany 161

iGuard/inSight User Guide Release 7.0.0.4 71 Note: If you are entering these content types manually, they must be typed exactly as they app

Strany 163 - 10. Save

Reconnex Corporation 72 Release 7.0.0.4 Content Types Formats C++_Source, Cobol_Source, FORTRAN_Source, Java_Source, JavaScript, LISP_Sourc

Strany 164 - View Objects

iGuard/inSight User Guide Release 7.0.0.4 73 iGuard assigns three tokens to each email address: the username, hostname, and domain name. By

Strany 165 - System Logging

Reconnex Corporation 74 Release 7.0.0.4 Search by IP Address You can search for individual IP addresses, a subnet, or a range of addresses.

Strany 166

iGuard/inSight User Guide Release 7.0.0.4 75 Find all of the words In this search, the AND operator is implied. Because the query does not

Strany 167 - Managing Disk Space

Reconnex Corporation 76 Release 7.0.0.4 Find at least one of the words \

Strany 168 - Using Directory Services

iGuard/inSight User Guide Release 7.0.0.4 77 Without the words Search by Location To search by location, go to Capture > Basic Search &

Strany 169 - Using an LDAP Server

Reconnex Corporation 78 Release 7.0.0.4 Search by Port Number Because IANA (Internet Assigned Numbers Authority) maintains a list of well-k

Strany 170

iGuard/inSight User Guide Release 7.0.0.4 79 Search by Protocol Searching for a protocol in captured results will return all traffic transm

Strany 171

Reconnex Corporation 80 Release 7.0.0.4 Search by Time All objects captured by iGuard are time-stamped. Defining a time period will narrow

Strany 172

iGuard/inSight User Guide Release 7.0.0.4 81 Search by User ID If you know a user's handle, you can search for it. Go to Capture >

Strany 173

iGuard/inSight User Guide Release 7.0.0.4 1 The Reconnex Solution Reconnex iGuards are at the heart of the Reconnex solution. They intelligentl

Strany 174 - Managing Devices

Reconnex Corporation 82 Release 7.0.0.4 Once it is created, you can then use that template repeatedly instead of creating the same query m

Strany 175

iGuard/inSight User Guide Release 7.0.0.4 83 4. Apply. 5. Search. Search Limitations Like other search engines, iGuard has some capacit

Strany 176

Reconnex Corporation 84 Release 7.0.0.4 /> ]]> markup * control characters / escape characters If you enter any of these characters

Strany 177 - Contact Technical Support

iGuard/inSight User Guide Release 7.0.0.4 85 If your search takes more than 30 seconds to complete, the process will be backgrounded and y

Strany 178 - Power Redundancy

Reconnex Corporation 86 Release 7.0.0.4 You can develop that template by experimenting with multiple search terms. The following example c

Strany 179 - Reliable Earthing

iGuard/inSight User Guide Release 7.0.0.4 87 Examples mailfrom:John AND mailto:Mary + "Confidential" subj:"Technical Suppor

Strany 180

Reconnex Corporation 88 Release 7.0.0.4 What are Policies? Policies are sets of rules that search your data stream for specific incidents o

Strany 181 - Release 7.0.0.4

iGuard/inSight User Guide Release 7.0.0.4 89 Electronic Risk Modules (ERMs) ERMs Electronic Risk Modules refer to packages of standard poli

Strany 182

Reconnex Corporation 90 Release 7.0.0.4 Think of the inheritance state as a toggler. If a rule's Inherit Policy State is Enabled, it m

Strany 183

iGuard/inSight User Guide Release 7.0.0.4 91 4. Select an activation state. 5. Select a publication state by checking a deployment box un

Komentáře k této Příručce

Žádné komentáře