Can Sep firewall do that?

This issue has been solved. See solution.
Fatih Teke's picture

Hello everybody.
We can block web sites with  address or ip address. For example i blocked www.test.com sep firewall cannot access this address. It's mean Sep firewall can read user request. well my qestion is;
Sep firewall can log user request ?
Can i take internet access report or read user internet access?
for example time,address, use time etc.?
Best Regards.
Fatih

Manish@symantec's picture

hi, The answer to your

hi,

The answer to your question is Yes.

This is possible by enabling the "writing to the desired log" feature in Firewall Rules. A small screenshot shown below may help you for the same.

fr.JPG

6.JPG

regards,

MG.
Symantec Corp.

Fatih Teke's picture

Thank you

Hello Manish.
thank you for answer.
Can i ask more please?
How can i read this firewall logs whithout connect to client computer?
Which rule should i log?Am i create new rule for all access?
Fatih.

------------------------------------------
Everything works better when everything works together.

Manish@symantec's picture

How can i read this firewall

How can i read this firewall logs whithout connect to client computer?
-> You can pull up reports from Monitors > Log tab. Over there, you will find a number of filters for the logs that you wish to see.

Which rule should i log?Am i create new rule for all access?
-> The Rule for which you want the logs to be written. eg. you create a rule to block abc.com, you can enable write to Log option for that Rule.

regards,

MG.
Symantec Corp.

Bijay.Swain's picture

If you create firewall rule

If you create firewall rule for each website then sep can log the websites access by users which is impossible.

yes you can create a firewall rule for clients internet explorer which will log the websites visited but you can not access those logs from sepm.

this should be done from your proxy server.

Fatih Teke's picture

logs

ok i read it in logs page. there is too much log is written in there. can i delete old logs?

And i want to log all internet address access not only abc.com. how can i do that?
Thanks
Fatih.

------------------------------------------
Everything works better when everything works together.

Manish@symantec's picture

This how you can Pull up

This how you can Pull up Traffic log reports via the SEPM.

ntp.JPG

regards,

MG.
Symantec Corp.

Fatih Teke's picture

Hello Vikram. Thanks for

Hello Vikram.
Thanks for answer. But Can i delete old logs?
Thanks

------------------------------------------
Everything works better when everything works together.

Vikram Kumar-SAV to SEP's picture

program

program files\symantec\Symantec Endpoint Protection Manager\data\inbox\log


Celebrating 2 years as a community member....

Fatih Teke's picture

Realy Thanks

Hello Vikram.
Thank you so much.
Best Regards.
Fatih

------------------------------------------
Everything works better when everything works together.