Setting up notifications for firewall rule violations

Article:HOWTO81221  |  Created: 2012-10-24  |  Updated: 2013-10-07  |  Article URL http://www.symantec.com/docs/HOWTO81221
Article Type
How To


Subject


Setting up notifications for firewall rule violations

You can configure Symantec Endpoint Protection to send you an email message each time the firewall detects a rule violation, attack, or event. For example, you may want to know when a client blocks the traffic that comes from a particular IP address.

To set up notifications for firewall rule violations

  1. In the console, open a Firewall policy.

  2. On the Firewall Policy page, click Rules.

  3. On the Rules tab, select a rule, right-click the Logging field, and do one or more of the following tasks:

    To send an email message when a firewall rule is triggered

    Check Send Email Alert.

    To generate a log event when a firewall rule is triggered

    Check both Write to Traffic Log and Write to Packet Log.

  4. When you are done with the configuration of this policy, click OK.

  5. Configure a security alert.

  6. Configure a mail server.

  7. Click OK.

See Setting up firewall rules

See Customizing firewall rules.

See Setting up administrator notifications


Legacy ID



v9504492_v81626096


Article URL http://www.symantec.com/docs/HOWTO81221


Terms of use for this information are found in Legal Notices