|
For the latest list of Frequently Asked Questions on Firewall Analyzer, visit the FAQ on the website or the public user forums.
Protocols in Reports
Different firewalls denote the port numbers in the logs in different ways, for example, http:80 can be shown as tcp:80, http:80, etc. Hence, the protocol identifiers are grouped as Protocols and then to Protocol Groups. We found that the reports using Protocols are much usable than the reports based on port numbers. Hence, we show the Protocols in the reports. If all the unassigned protocols assigned to Protocols and Protocol Groups, there would not be any issue of unknown protocols.
Assigning Unassigned Protocols
There will be some unassigned protocols as few protocols are not grouped.
You can view the port details of theunassigned protocols:
We have configured the generally used protocols as Groups like Mail, Web, FTP, Telnet, etc. However, you can group the unknown protocols as per your requirement. Configuring Unassigned Protocol will be a one-time activity.
Note:Once you assign the protocols, the reports will show the assigned protocols and the newly assigned protocols under their appropriate protocol group only from the assigned time. You will see the unassigned protocols in the reports generated earlier to the assigned time.
If you find that the reports based on ports, please assign specific protocols to the corresponding port numbers and create a custom report to view the details.
Checking the port numbers
General
CheckPoint Firewall Reports
Cisco PIX Firewall Reports
NetScreen Firewall Reports (Syslog)
Other Firewall Reports (Sonicwall, Fortigate, and all other firewall's that support WELF)
|