cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

send email on access from designated country

I have a requirement to send an email alert when NSM/NS-7150 detects attempted access from designated countries.  I have been looking at this and have not yet figured out how to do this.

 

First question is this possible at all? I have found the firewall policies and added a policy but it does not have an action available to send an alert.

Is it possible to get a pointer to the applicable manual? I have not found it yet on my google searches. I will RTFM if I could figure out which manual.

NSM version 9.2.7.31 (Yes I know it is dated but i have configuration control requirements that prevent me from updating at this time).

Tom

3 Replies
McAfee Employee fkazi04
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: send email on access from designated country

Hi @Tom5451C ,

 

Email notifications can be configured for IPS Events/Configuration reports.

You may set up a Syslog notification for a firewall rule match if the action is NOT configured as stateless. It is not possible to have an email notification for traffic matching a firewall rule. Upgrading the Manager/Sensor to the latest build will not help to get the above requirement fulfilled. 

 

I hope this answers your question.

 

Regards,

Faizan

 

Was my reply helpful?

If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

 

 

Regards,
Faizan

Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
McAfee Employee tsrivast
McAfee Employee
Report Inappropriate Content
Message 3 of 4

Re: send email on access from designated country

Step 1 is to  Make sure that the country location database is present on the box, then only country specific rule will work.

For that execute status command on the sensor and check for the highlighted value below 

 

[Signature Status]
Present : yes
Version : 10.8.0.6
Power up signature : good
Geo Location database : Present
DAT file : Present
DAT file Version : 2497.0

 

If the database is present you can create country specific rule followed by enabling syslog forwarding settings on the firewall policy as mentioned in the above post.

If syslog notification helps for you its good, else you can create a Product Enhancement Request using the below KB

 

https://kc.mcafee.com/corporate/index?page=content&id=KB60021

 to include email notification feature over firewall policy on the senor 

Was my reply helpful?


If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

 

 

Very Respectfully,

Tarang Srivastava 

McAfee Technical Support

 

 

 

 

 

Re: send email on access from designated country

Both above responses were clear and helpful but since there appears to be no way of doing what I wanted to I cannot accept them as a solution. Partial solutions but not a complete one yet.

 

I will look deeper into the "log to syslog" option and I may see a solution when that is integrated into our SIEM. Syslog sent to SIEM, SIEM then takes responsibility for sending out the email as necessary.

 

Thanks.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community