Ask the Community
Groups
Watchguard - Connect IT Community | Kaseya
<main> <article class="userContent"> <h2 data-id="review-configuration-options-for-watchguard-firewalls-in-rocketcyber">Review configuration options for WatchGuard firewalls in RocketCyber</h2> <table border="1" cellpadding="4"><tbody><tr><td>DDoS attack</td> <td>Detects attempts to crash your network by overwhelming available resources. <br>This can take the form of using all available bandwidth, memory, or other network resources</td> </tr><tr><td>Port scan</td> <td>Detects malicious actors attempting to discover what ports are open on your network</td> </tr><tr><td>IPS detection (general)</td> <td>Detections from the WatchGuard Intrusion Prevention System (IPS)</td> </tr><tr><td>APT detection</td> <td>Detections from WatchGuards Advanced Persistent Threat tools</td> </tr><tr><td>Data leak</td> <td>Detects your network leaking data</td> </tr><tr><td>Reputation lookup</td> <td>Determines whether traffic originated from a known malicious IP address</td> </tr><tr><td>IP spoofing</td> <td>Detects attempts to change the reported source of traffic entering your network (for example, to avoid reputation lookups)</td> </tr><tr><td>IPS license expired</td> <td>A friendly reminder when your IPS license expires</td> </tr><tr><td>ICMP, IKE, IPSEC, UDP flood attacks</td> <td>Various methods of overwhelming network resources to crash your network</td> </tr><tr><td>GAV Virus</td> <td>A virus detected at your gateway</td> </tr><tr><td>Detect VPN use</td> <td>This will monitor and inform you if someone enables or attempts to use a VPN on your network.<br><em>Only use this if VPN should be disabled on your network!</em> </td> </tr></tbody></table><p> </p> <h3 data-id="log-format">Log Format</h3> <p>The expected format for WatchGuard logs is <strong>space-separated</strong>. For example</p> <p><140>Feb 4 10:47:38 ABC-FW 8265941A0BAD (2020-02-04T15:47:38) firewall: msg_id="3000-0148" Allow 1-Trusted 0-External 52 tcp 20 127 192.168.101.12 24.102.62.243 31757 443 offset 8 S 2947993982 win 32 geo_dst="USA" (HTTPS-proxy-00)</p> </article> </main>