Event Manager for NetScreen Firewalls

Release Notes

Date Published: May 2009

 
 

 

Event Manager for Firewalls allows you to monitor NetScreen firewall devices. By detecting, alerting on, and automatically responding to critical events in realtime, Event Manager for Firewalls helps indicate, correct, and prevent possible external intrusions, attacks, and configuration problems.

Event Manager for Firewalls monitors syslog messages generated by NetScreen firewall devices. Event Manager for Firewalls highlights events that may indicate configuration changes or external attacks, so you can quickly take corrective or preventive actions. For example, Event Manager for Firewalls enables you to perform the following tasks:

  • Detect misconfigurations in your firewall environment
  • Monitor failover between primary and standby firewalls
  • Identify attacks, such as unusual port scans, and then respond with an alert
  • Identify policy misuse
  • Trace administrative access and actions
  • Notify the Security Specialists notification group of serious issues
  • Monitor your environment from a single console

Supported Products

This release supports the following products:

  • NetScreen firewalls with ScreenOS 5.x
  • NetScreen firewalls with ScreenOS 6.x

Return to Top

Why Install This Module?

Event Manager for Firewalls provides the following important new capabilities:

  • Adds support for NetScreen ScreenOS 6.x
  • Improves usability of rules and views

Improvements are made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs.

Return to Top

System Requirements

The following table lists additional requirements for a Windows agent acting as the proxy agent for NetScreen firewall devices. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.

Category Requirement
Processor 1.5 GHz Intel Pentium III or equivalent.
Memory 40 MB minimum. The amount of memory usage varies and depends on the environment, including event rate and other factors. Memory use for a Windows agent monitoring NetScreen Firewall could reach 256 MB or higher.
Operating System All supported Windows agent platforms.
Software
  • Ensure you have Security Manager 6.5 or later installed.
  • A Windows agent can monitor one or more NetScreen firewalls. For more information about the number of instances one agent can support, see the NetIQ Security Manager Knowledge Base article NETIQKB51404 at www.netiq.com/support/sm/.
  • If the NetScreen device and the agent are separated by a firewall, ensure the firewall allows syslog data through.
  • Install each Windows agent on a subnet as physically close to the firewall as possible. Fewer network hops provide better performance.
  • Install the Windows agent with NetScreen support on a separate computer from the database server or central computer.

Return to Top

Installing This Module

Complete the following steps to install this module in a new Security Manager 6.5 installation.

To install this module:

  1. Open the Module Installer. Under Event Manager for Firewalls, the Module Installer lists both a Legacy and a non-Legacy version of the NetScreen Firewall module.
  2. Select only the non-Legacy version of the module and click Install.
  3. Configure the new module using the Configuration Wizard. For more information about accessing the Configuration Wizard, see the User Guide for NetIQ Security Manager. For more information about how to enter information, click the question mark in the bottom left of the Configuration Wizard to expand a Help window to the right.
  4. Configure the Windows agent. For more information, see the Installation Guide for NetIQ Security Manager.
  5. Configure the NetScreen firewall device to communicate with the Windows agent. For more information, see Configuring the NetScreen Firewall Device.

Return to Top

Upgrading This Module

After you have upgraded your existing installation to Security Manager 6.5, complete either step 1 or step 2 in the following procedure to upgrade a previous version of this module.

To upgrade this module:

  1. If you have access to reconfigure the NetScreen firewall devices and have an extra computer on which to install a new Security Manager 6.5 Windows agent, complete the following steps:
    1. Install and configure a new Security Manager 6.5 Windows agent to receive syslog messages. For more information, see the Installation Guide for NetIQ Security Manager.
    2. Open the Module Installer. Under Event Manager for Firewalls, the Module Installer lists both a Legacy and a non-Legacy version of the NetScreen Firewall module.
    3. Select both the Legacy and non-Legacy versions of this module and click Install. If you do not install the Legacy version of NetScreen Firewall, two instances of Configure the module for NetScreen Firewall will appear in the Support for Firewalls section of the Configuration Wizard. You will then have to open each instance to see which one is Legacy. When you install both versions, Security Manager renames Configuration Wizard links, existing rule groups, and documentation so you can easily distinguish between legacy items and new items, minimizing confusion.
    4. When the modules are installed, open the Configuration Wizard.
    5. In the left pane, click Support for Firewalls.
    6. Click Configure the module for NetScreen Firewall.
    7. In the left pane, click Agents that monitor NetScreen Firewall.
    8. Add the new Security Manager 6.5 Windows agent you just installed.
    9. In the left pane, click NetScreen Firewall Devices.
    10. Add the NetScreen firewall devices from which you want the new Windows agent to receive data.
    11. Click Finish.
    12. Access the NetScreen firewall devices and reconfigure them to send data to the new Windows agent. For more information, see Configuring the NetScreen Firewall Device.
    13. Verify the new NetScreen Firewall computer groups are populated with data.
    14. Open the Configuration Wizard.
    15. In the left pane, click Support for Firewalls.
    16. Click Configure the module for NetScreen Firewall (Legacy).
    17. Remove all agents and devices, disabling the Legacy version of the module.
    18. Warning
      Ensure you have already reconfigured the NetScreen firewall devices to forward their syslog events to the new agent before you disable the Legacy version of the module, otherwise you will lose data.

    19. Click Finish.
    20. In the Schedule Configuration Changes window, select both checkboxes and click OK.
  2. If you do not have easy access to reconfigure NetScreen firewall devices or you do not have an extra computer on which to install a new Security Manager 6.5 Windows agent, complete the following steps:
  3. Note
    If you do not complete the following steps in a timely manner, it is possible some data collected will be stored as unrecognized syslog events in the log archive under source Generic Syslog.

    1. Open the Module Installer. Under Event Manager for Firewalls, the Module Installer lists both a Legacy and a non-Legacy version of the NetScreen Firewall module.
    2. Select both the Legacy and non-Legacy versions of this module and click Install. If you do not install the Legacy version of NetScreen Firewall, two instances of Configure the module for NetScreen Firewall will appear in the Support for Firewalls section of the Configuration Wizard. You will then have to open each instance to see which one is Legacy. When you install both versions, Security Manager renames Configuration Wizard links, existing rule groups, and documentation so you can easily distinguish between legacy items and new items, minimizing confusion.
    3. When the modules are installed, open the Configuration Wizard.
    4. In the left pane, click Support for Firewalls.
    5. Click Configure the module for NetScreen Firewall (Legacy).
    6. Take note of all settings:
      • Agent domains and names
      • Device names
      • Monitoring settings
    7. Clear all entries, disabling the module.
    8. Click Finish.
    9. In the Schedule Configuration Changes window, ensure both checkboxes are cleared.
    10. Warning
      Selecting these options will result in data loss as the agents you have removed will stop receiving data from your NetScreen firewall devices.

    11. Click OK.
    12. Click Configure the module for NetScreen Firewall.
    13. Configure the non-Legacy version of NetScreen Firewall with the settings you recorded earlier from the Legacy version.
    14. Click Finish.
    15. In the Schedule Configuration Changes window, select both checkboxes and click OK. Selecting both options forces the Legacy module to empty all of its computer groups, causing the version 6.5 module to fill up its computer groups with all of the newly dropped agents and devices.
    16. If you want to configure additional NetScreen firewall devices in your installation, configure the Windows agent and then configure the NetScreen firewall device. For more information, see Configuring the Agent and Configuring the NetScreen Firewall Device.

Return to Top

Configuring the Agent

Add the name and IP address of the NetScreen firewall device to the Hosts file on the Windows agent computer. For more information about the Hosts file, see the Windows documentation.

Return to Top

Configuring the NetScreen Firewall Device

NetScreen firewalls require configuration before Event Manager or Log Manager can begin monitoring or collecting data from them. Configure each NetScreen firewall device to forward syslog messages to the Windows agent acting as the proxy agent.

To configure support for NetScreen:

  1. Configure the NetScreen firewall to send syslog messages to the Windows agent.

    If you want to receive traffic messages on your Windows agent, turn on Syslog Traffic Messaging.

    You will receive a large number of messages with this option. Security Manager stores them for log analysis, but does not report them as they occur.

  2. Configure the NetScreen firewall to report only the messages with the severity you want to monitor. For example, debug messages should normally be disabled due to the high number of messages created when debug messages are reported.
  3. On the NetScreen device, disable syslog VPN and enable Syslog.
  4. If your NetScreen syslog messages have a time stamp, ensure the time stamp has a year, month, day, hour, minutes, and seconds in the format YYYY-MM-DD-hh-mm-ss.
  5. Note
    If your NetScreen syslog messages do not have a time stamp in the right format, Security Manager uses the local time of the agent for the log message time.

Return to Top

Contact Information

Please contact us with your questions and comments. We look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

Return to Top

Legal Notice

Return to Top