I have a requirement to send an email alert when NSM/NS-7150 detects attempted access from designated countries. I have been looking at this and have not yet figured out how to do this.
First question is this possible at all? I have found the firewall policies and added a policy but it does not have an action available to send an alert.
Is it possible to get a pointer to the applicable manual? I have not found it yet on my google searches. I will RTFM if I could figure out which manual.
NSM version 9.2.7.31 (Yes I know it is dated but i have configuration control requirements that prevent me from updating at this time).
Tom
Hi @Tom5451C ,
Email notifications can be configured for IPS Events/Configuration reports.
You may set up a Syslog notification for a firewall rule match if the action is NOT configured as stateless. It is not possible to have an email notification for traffic matching a firewall rule. Upgrading the Manager/Sensor to the latest build will not help to get the above requirement fulfilled.
I hope this answers your question.
Regards,
Faizan
Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Step 1 is to Make sure that the country location database is present on the box, then only country specific rule will work.
For that execute status command on the sensor and check for the highlighted value below
[Signature Status]
Present : yes
Version : 10.8.0.6
Power up signature : good
Geo Location database : Present
DAT file : Present
DAT file Version : 2497.0
If the database is present you can create country specific rule followed by enabling syslog forwarding settings on the firewall policy as mentioned in the above post.
If syslog notification helps for you its good, else you can create a Product Enhancement Request using the below KB
https://kc.mcafee.com/corporate/index?page=content&id=KB60021
to include email notification feature over firewall policy on the senor
Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Very Respectfully,
Tarang Srivastava
McAfee Technical Support
Both above responses were clear and helpful but since there appears to be no way of doing what I wanted to I cannot accept them as a solution. Partial solutions but not a complete one yet.
I will look deeper into the "log to syslog" option and I may see a solution when that is integrated into our SIEM. Syslog sent to SIEM, SIEM then takes responsibility for sending out the email as necessary.
Thanks.
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center
Corporate Headquarters
2821 Mission College Blvd.
Santa Clara, CA 95054 USA