Intrusion Logging Help

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Intrusion Logging Help

Postby mcb » Oct 07 04 7:48 am

Hey Gaters,

Below I have copied a paragraph from the Wingate Help file.

"Intrusion Logging. You are instantly alerted to any intrusion attempts or suspicious activity with a WinGate system log message (see Port Security).
© Qbik New Zealand Limited 2001"

I have a question regarding what actually is the "instant alert" and how you configure.

What i would like to do:

Have some alert that can tell me when an unknown IP address has made it on my internal network. Say that i am using the traditional internal class C subnet, how do i set it to alert when WAN IP's have become part of the network. And when i mean alert it is usually hepful that have something that comes to you instead of the vice of the verse.

Is there some scheme that i could set up in "Port security, IP Blackhole or Policies" that would accomplish this?

Thanks,

Matt
mcb
 
Posts: 41
Joined: Aug 07 04 7:36 am
Location: NE Tennessee

Postby Pascal » Oct 07 04 9:54 am

From what I can see in the helpfile that refers to the ability to notify yourself when the port range is accessed. So in your case, I don't think that will do what you like.

However, NetPatrol could be well suited for that. It is an Intrusion Detection System and has a good array of logging, notification, etc. features. It is available on a trial license.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby genie » Oct 07 04 10:26 am

Moreover, NetPatrol is able to communicate with Wingate so that if the potential intrustion is detected, NetPatrol automatically blocks the offender for the certain period of time and issues a warning, which can be delivered via email to the administrator.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am


Return to WinGate

Who is online

Users browsing this forum: No registered users and 8 guests

cron