Network Instruments GigaStor 114ff Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Manuais de software Network Instruments GigaStor 114ff. Network Instruments GigaStor 114ff User's Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 146
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes

Resumo do Conteúdo

Página 1 - GIGASTOR

1rev. 1GIGASTOR™

Página 2

10rev. 1Tapping a WAN connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 3 - GigaStor User Guide

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort100rev. 1right-click menu. You can also jump to the Decode display

Página 4 - Limited Warranty—Hardware

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort101rev. 1Table 8 Forensic Analysis Profile Settings tabField Descr

Página 5 - Liability

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort102rev. 1TCP Stream Reassembly (Continued)Q Log preprocessor events

Página 6 - Ownership and Confidentiality

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort103rev. 1TCP Stream Reassembly (Continued)Q Reassembly error action

Página 7 - Technical Support

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort104rev. 1HTTP URI Normalization (Continued)Q Normalize percent-U en

Página 8

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort105rev. 1ARP Inspection Ethernet uses Address Resolution Protocol (

Página 9 - Contents

Forensic Analysis Profile field descriptionsChapter 6 Forensic Analysis using Snort106rev. 1Rules tabThe web site www.snort.org provides Snort rule do

Página 10

Chapter 7 Observer on the GigaStor107rev. 1C h a p t e r 7

Página 11

Using the Observer console locally on the GigaStorChapter 7 Observer on the GigaStor108rev. 1Using the Observer console locally on the GigaStorDependi

Página 12

Using the Observer console locally on the GigaStorChapter 7 Observer on the GigaStor109rev. 1Figure 74 Probe Options3 In the Service Settings section

Página 13 - About the GigaStor

11rev. 1Chapter 7: Observer on the GigaStorUsing the Observer console locally on the GigaStor . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 14 - GigaStor versions

Using the Observer console locally on the GigaStorChapter 7 Observer on the GigaStor110rev. 15 Choose Options → Switch between Observer and Expert Pro

Página 15 - Chapter 1 About the GigaStor

Chapter 8 Probe Instances111rev. 1C h a p t e r 8

Página 16

What is a probe instance?Chapter 8 Probe Instances112rev. 1What is a probe instance?TIP!For instructions on setting up a probe instance, see “Probeadm

Página 17 - Installing Your GigaStor

What is a probe instance?Chapter 8 Probe Instances113rev. 1instances to the Gen2 adapter if at all possible. A copy of allpackets are sent from the ad

Página 18

What is a probe instance?Chapter 8 Probe Instances114rev. 1NOTE:By default there is one active probe instance for GigaStor. Itbinds to the network ada

Página 19

Chapter 9 Gen2 Capture Card115rev. 1C h a p t e r 9

Página 20

Swapping the Gen2 card’s SFP or XFP interfacesChapter 9 Gen2 Capture Card116rev. 1The Gen2 card is designed and manufactured by Network Instruments an

Página 21

Configuring virtual adapters on the Gen2 cardChapter 9 Gen2 Capture Card117rev. 1Q Ports 1-4 are monitoring a collection of trunked linksQ The remaini

Página 22

Configuring virtual adapters on the Gen2 cardChapter 9 Gen2 Capture Card118rev. 1Figure 78 Assign Port to Virtual Adapter: Default view3 Select the p

Página 23

Configuring virtual adapters on the Gen2 cardChapter 9 Gen2 Capture Card119rev. 1Figure 80 Edit Port Description9 Repeat step 5 through step 8 until

Página 25

Viewing the Gen2 card’s properties and finding the board’s IDChapter 9 Gen2 Capture Card120rev. 110 Right-click the GigaStor probe and choose Administ

Página 26

Viewing the Gen2 card’s properties and finding the board’s IDChapter 9 Gen2 Capture Card121rev. 12 In the tree on the left, select Device Manager.3 In

Página 27

Viewing the Gen2 card’s properties and finding the board’s IDChapter 9 Gen2 Capture Card122rev. 1This tab shows all active physical ports on the Gen2

Página 28

Appendix A TCP/IP ports, NAT, and VPN123rev. 1A p p e n d i x A

Página 29 - GigaStor Capture Analysis

TCP/IP portsAppendix A TCP/IP ports, NAT, and VPN124rev. 1This section discusses the TCP/IP ports, NAT, and VPN.TCP/IP portsObserver and all Network I

Página 30

VPNAppendix A TCP/IP ports, NAT, and VPN125rev. 1Figure 86 NATIf the Observer is outside the network where the probe is running, you must forward por

Página 31

VPNAppendix A TCP/IP ports, NAT, and VPN126rev. 1

Página 32

Appendix B GigaStor, GigaStor Expandable, and Expansion Unit Cases127rev. 1A p p e n d i x B

Página 33

GigaStorAppendix B GigaStor, GigaStor Expandable, and Expansion Unit Cases128rev. 1GigaStorFigure 87 shows the front of the GigaStor.Figure 87 GigaSt

Página 34

GigaStor ExpandableAppendix B GigaStor, GigaStor Expandable, and Expansion Unit Cases129rev. 1GigaStor ExpandableController unitFigure 88 GigaStor Ex

Página 35 - Digital T1/E1 Probe Settings

Chapter 1 About the GigaStor13rev. 1C h a p t e r 1

Página 36 - Serial T1/E1 Probe Settings

GigaStor ExpandableAppendix B GigaStor, GigaStor Expandable, and Expansion Unit Cases130rev. 1Figure 89 shows the back of the GigaStor Expandable.Figu

Página 37 - Q Optical TAP

GigaStor ExpandableAppendix B GigaStor, GigaStor Expandable, and Expansion Unit Cases131rev. 1Figure 91 shows the back of the expansion unit.Figure 91

Página 38

GigaStor ExpandableAppendix B GigaStor, GigaStor Expandable, and Expansion Unit Cases132rev. 1

Página 39 - NIC for TCP/IP

Appendix C GigaStor Portable133rev. 1A p p e n d i x C

Página 40 - Gigabit copper

Appendix C GigaStor Portable134rev. 1The portable GigaStor offers full-duplex packet capture and analysis at wire speed. Depending on which version yo

Página 41

Appendix C GigaStor Portable135rev. 1Figure 92 Portable Analysis Platform System TourYour GigaStor includes a number of components. Take a moment aft

Página 42 - Tapping a WAN connection

Running Observer passivelyAppendix C GigaStor Portable136rev. 1Figure 93 Portable GigaStorGigabit and Fibre Channel systems have an appropriate coppe

Página 43

Using the portable GigaStor as a probeAppendix C GigaStor Portable137rev. 1Dynamic Host Control Protocol (DHCP). For most applications of Observer, yo

Página 44

Using the portable GigaStor as a probeAppendix C GigaStor Portable138rev. 1

Página 45 - Observer Console

Numerics–DIndex139rev. 1Legend: ff=Figure, t=TableIndexNumerics10 Gigabit Ethernet 14, 37, 116Gen2 card 37GigaStor Portable 134tapping 1910/100/1000 3

Página 46

GigaStor versionsChapter 1 About the GigaStor14rev. 1GigaStor versionsThe GigaStor is an enterprise-strength network probe appliance. The GigaStor com

Página 47 - Figure 29 DS3/E3 TAP

E–GIndex140rev. 1Legend: ff=Figure, t=TableT1/E1 42WAN alarms 90WAN statistics 80, 82–83DCE BECN under CIR 84DCE FECN under CIR 84DCE Kbits/s Avg 84DC

Página 48 - Serial/HSSI

H–IIndex141rev. 1Legend: ff=Figure, t=Tabledaughter board 38DMA enabled 122Fibre Channel 37filter ports 66Gigabit 37Gigabit copper 40Interrupt enabled

Página 49 - Figure 30 WAN HSSI

L–PIndex142rev. 1Legend: ff=Figure, t=TableLLAPB 34–35loadpreprocess settings 101preprocessor 113MMAC address 105DLCI instead of 80excluding 65statist

Página 50

Q–VIndex143rev. 1Legend: ff=Figure, t=TableProbe Properties T1/E1 Tab 35Probe Service Configuration Applet 21ff, 108ffQQLogic 19Quality of Service 32R

Página 51 - GigaStor (16 drive)

W–XIndex144rev. 1Legend: ff=Figure, t=Tablevirtual adapter 114ffprobe instances 119–120Virtual Adapters tab 119ffVPN 125WWANalarms 80, 88analysis 80an

Página 53

146rev. 1www.networkinstruments.com © 2008 Network Instruments, LLC. All rights reserved. Network Instruments, Observer, and all associated logos are

Página 54

GigaStor versionsChapter 1 About the GigaStor15rev. 1possible to use the same probe to monitor different types of links as needed. For example, you ca

Página 55

GigaStor versionsChapter 1 About the GigaStor16rev. 1

Página 56

Chapter 2 Installing Your GigaStor17rev. 1C h a p t e r 2

Página 57 - GigaStor Control Panel

Unpacking and inspecting the partsChapter 2 Installing Your GigaStor18rev. 1The general steps to install your GigaStor are:F “Unpacking and inspecting

Página 58

Installing the GigaStor and connecting the cablesChapter 2 Installing Your GigaStor19rev. 1Installing the GigaStor and connecting the cables1 Install

Página 60 - Right-click menus

Setting the GigaStor’s IP addressChapter 2 Installing Your GigaStor20rev. 14 Ensure that each drive’s power/activity light is lit. If a drive’s light

Página 61 - Analyze button

Setting the GigaStor’s IP addressChapter 2 Installing Your GigaStor21rev. 1Figure 3 Probe Service Configuration Applet10 The Probe Administration win

Página 62

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor22rev. 1Connecting Observer to the GigaStorThis section assumes you have already

Página 63

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor23rev. 1Figure 6 Edit Remote Probe Entry4 Type the IP address that you assigned

Página 64 - GigaStor Options tab

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor24rev. 1Figure 8 Probe Instance Redirection6 Select the probe instance and click

Página 65 - Table 5 GigaStor Options tab

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor25rev. 11 Click Probe Administration (see Figure 7). The Probe Administration Log

Página 66

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor26rev. 1By default all of the installed memory on the GigaStor is dedicated for o

Página 67 - GigaStor Outline

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor27rev. 1Figure 13 GigaStor Instances7 Click New Instance. Figure 14 appears.Figu

Página 68 - Figure 41 GigaStor Outline

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor28rev. 1Figure 15 Edit Probe Instance: Configure Memory9 From the RAM that you r

Página 69 - Capture Graph tab

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor29rev. 111 Repeat step 7 through step 10 until you have created all of your probe

Página 70 - GigaStor Schedule tab

3rev. 1GigaStor User Guide

Página 71 - Statistics Lists tab

Connecting Observer to the GigaStorChapter 2 Installing Your GigaStor30rev. 1Figure 18 GigaStor Settings Schedule tab3 In the Schedule GigaStor Captu

Página 72

Configuring Observer for your Gigabit deviceChapter 2 Installing Your GigaStor31rev. 1Configuring Observer for your Gigabit deviceDepending on your pr

Página 73

Configuring Observer for your Gigabit deviceChapter 2 Installing Your GigaStor32rev. 1Figure 19 Gigabit tabConfiguring Terms of Service and Quality o

Página 74

Configuring Observer for your WAN deviceChapter 2 Installing Your GigaStor33rev. 1Figure 20 ToS/QoS tabConfiguring Observer for your WAN deviceThere

Página 75 - GigaStor reports

Configuring Observer for your WAN deviceChapter 2 Installing Your GigaStor34rev. 1Digital DS3/E3/HSSI Probe SettingsTo access the probe settings, sele

Página 76

Configuring Observer for your WAN deviceChapter 2 Installing Your GigaStor35rev. 1Digital T1/E1 Probe SettingsTo access the probe settings, select the

Página 77

Configuring Observer for your WAN deviceChapter 2 Installing Your GigaStor36rev. 1Serial T1/E1 Probe SettingsTable 3 describes fields for a serial T1/

Página 78

Tapping an Ethernet or Fibre Channel connectionChapter 2 Installing Your GigaStor37rev. 1Tapping an Ethernet or Fibre Channel connectionThis section d

Página 79

Tapping an Ethernet or Fibre Channel connectionChapter 2 Installing Your GigaStor38rev. 1Figure 23 Gen2 card port assignments6 Use the supplied Ether

Página 80 - Discover Network Names

Tapping an Ethernet or Fibre Channel connectionChapter 2 Installing Your GigaStor39rev. 1Figure 24 GigaStor with an optical nTAPTXRXGigabit Switch (D

Página 81

4rev. 1Trademark Notices©2008 Network Instruments,® LLC. All rights reserved. Network Instruments, Observer® Gen2,TM and all associated logos are tra

Página 82 - WAN Bandwidth Utilization

Tapping an Ethernet or Fibre Channel connectionChapter 2 Installing Your GigaStor40rev. 1Gigabit copperThe Gigabit copper kit includes:Q Copper nTAPQ

Página 83 - WAN Vital Signs by DLCI

Tapping an Ethernet or Fibre Channel connectionChapter 2 Installing Your GigaStor41rev. 16 Use the supplied Ethernet cable to connect the network inte

Página 84 - WAN Load by DLCI

Tapping a WAN connectionChapter 2 Installing Your GigaStor42rev. 1Tapping a WAN connectionThis section describes how to connect the cables for these e

Página 85

Tapping a WAN connectionChapter 2 Installing Your GigaStor43rev. 1Now that you have physically connected the cables for the GigaStor, you must now con

Página 86 - WAN Top Talkers

Tapping a WAN connectionChapter 2 Installing Your GigaStor44rev. 1SerialThe serial T1/E1 kit includes:Q One serial T1/E1 WAN TAPQ One serial Y cableQ

Página 87 - WAN Filtering

Tapping a WAN connectionChapter 2 Installing Your GigaStor45rev. 1Figure 28 WAN Serial T1/E1 TAPRouter (DCE)CSU/DSU (DTE)10/100/1000 NIC for TCP/IPGi

Página 88 - Triggers and Alarms

Tapping a WAN connectionChapter 2 Installing Your GigaStor46rev. 1DS3/E3See “Digital” on page 46 or “Serial/HSSI” on page 48 depending on your needs.D

Página 89 - Figure 62 Triggers tab

Tapping a WAN connectionChapter 2 Installing Your GigaStor47rev. 1Figure 29 DS3/E3 TAPPOWERDTEE3LOFLOSINOUTDCELOFLOSINOUTOUT (TX)IN (RX)RXRXDS3 Line

Página 90

Tapping a WAN connectionChapter 2 Installing Your GigaStor48rev. 1Serial/HSSIThe serial DS3 kit includes:Q One serial DS3/E3 TAPQ One HSSI Y-cableQ On

Página 91 - Forensic Analysis using Snort

Tapping a WAN connectionChapter 2 Installing Your GigaStor49rev. 1Figure 30 WAN HSSIRouter (DCE)CSU/DSU (DTE)10/100/1000 NIC for TCP/IPGigaStor orGig

Página 92

5rev. 1Limited Warranty—SoftwareNetwork Instruments, LLC (“DEVELOPER”) warrants that for a period of sixty (60) days from the date of shipment from DE

Página 93

Installing the drives in your GigaStorChapter 2 Installing Your GigaStor50rev. 1Installing the drives in your GigaStorCAUTION HANDLINGTHE DRIVESBe esp

Página 94

Installing the drives in your GigaStorChapter 2 Installing Your GigaStor51rev. 1Figure 31 shows how the drive numbers correspond to slot locations.Fig

Página 95

Installing the drives in your GigaStorChapter 2 Installing Your GigaStor52rev. 1Connecting the GigaStor Expandable to the expansion unitsAfter you hav

Página 96

Chapter 3 Packet Capture or GigaStor Capture53rev. 1C h a p t e r 3

Página 97

Capturing Packets with the GigaStorChapter 3 Packet Capture or GigaStor Capture54rev. 1Capturing Packets with the GigaStorA GigaStor can accumulate te

Página 98 - About Forensic Analysis tab

Packet capture buffer and statistics bufferChapter 3 Packet Capture or GigaStor Capture55rev. 1However, if you are pushing the limits of the system on

Página 99

Packet capture buffer and statistics bufferChapter 3 Packet Capture or GigaStor Capture56rev. 1

Página 100 - Q “Rules tab” on page 106

Chapter 4 GigaStor Control Panel57rev. 1C h a p t e r 4

Página 101

Chapter 4 GigaStor Control Panel58rev. 1Once the GigaStor is up and running on the network, you can run Expert Observer or Observer Suite to connect t

Página 102

Display ControlsChapter 4 GigaStor Control Panel59rev. 1etc., by clicking on the appropriate tab and selecting the items you want to see on the time l

Página 103

6rev. 1Ownership and ConfidentialityEND-USER agrees that Network Instruments, LLC owns all relevant copyrights, trade secrets and all intellectual pr

Página 104

Right-click menusChapter 4 GigaStor Control Panel60rev. 1Right-click menusAs with other Observer displays, the charts and tables of the GigaStor contr

Página 105

Analyze buttonChapter 4 GigaStor Control Panel61rev. 1Analyze buttonFigure 36 GigaStor Control Panel Analyze buttonWhen you click the Analyze button

Página 106 - Rules tab

Analyze buttonChapter 4 GigaStor Control Panel62rev. 1Figure 37 GigaStor Analysis Options windowTable 4 describes what the fields in the various sect

Página 107 - Observer on the GigaStor

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel63rev. 1Configuring the GigaStor through the Control PanelJust as wi

Página 108

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel64rev. 1GigaStor Options tabThis tab lets you configure many options

Página 109

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel65rev. 1Table 5 GigaStor Options tabField DescriptionCapture Buffer

Página 110

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel66rev. 1Start/Stop Packet Capture marker framesWhen checked, saved p

Página 111 - Probe Instances

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel67rev. 1GigaStor Chart tabThis tab lets you choose the appearance, c

Página 112 - What is a probe instance?

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel68rev. 1Figure 41 GigaStor Outline

Página 113

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel69rev. 1Capture Graph tabClick Settings and the tab for the type of

Página 114 - Chapter 8 Probe Instances

7rev. 1Technical SupportNetwork Instruments provides technical support by phone (depending on where you are located):US & countries outside Europe

Página 115 - Gen2 Capture Card

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel70rev. 1GigaStor Schedule tabThis tab lets you schedule GigaStor pac

Página 116 - Chapter 9 Gen2 Capture Card

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel71rev. 1Q Choose Daily at specified times or By day-of-week at speci

Página 117

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel72rev. 1Figure 44 Statistics Lists tabSubnetYou can specify subnet

Página 118

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel73rev. 1Figure 45 GigaStor Subnet tabFigure 46 shows how the subnet

Página 119

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel74rev. 1Figure 46 Subnet and IP Stations

Página 120

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel75rev. 1GigaStor reportsThere are several default reports available

Página 121

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel76rev. 1Figure 48 Report Setup3 Use the arrow buttons to position g

Página 122

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel77rev. 1ExportYou can export your GigaStor-collected data on a sched

Página 123 - TCP/IP ports, NAT, and VPN

Configuring the GigaStor through the Control PanelChapter 4 GigaStor Control Panel78rev. 1

Página 124 - TCP/IP ports

Chapter 5 Using Observer with a WAN Probe79rev. 1C h a p t e r 5

Página 126

Discover Network NamesChapter 5 Using Observer with a WAN Probe80rev. 1In general, the WAN analysis works much like Ethernet analysis. One difference

Página 127 - Expansion Unit Cases

Discover Network NamesChapter 5 Using Observer with a WAN Probe81rev. 1To set the CIR for a DLCI or group of DLCIs1 Choose Tools → Discover Network N

Página 128 - GigaStor

WAN Bandwidth UtilizationChapter 5 Using Observer with a WAN Probe82rev. 15 Click OK when you are done. For encapsulations that do not use DLCI (such

Página 129 - GigaStor Expandable

WAN Vital Signs by DLCIChapter 5 Using Observer with a WAN Probe83rev. 1WAN Vital Signs by DLCIIn Observer, the Network Vital Signs display is replace

Página 130 - Expansion unit

WAN Load by DLCIChapter 5 Using Observer with a WAN Probe84rev. 1WAN Load by DLCIIn a WAN installation, Observer’s Network Activity Display is called

Página 131 - Power Supply

WAN Load by DLCIChapter 5 Using Observer with a WAN Probe85rev. 1Figure 55 WAN Load by DLCIThe WAN Load by DLCI mode can be viewed as a dial, graph,

Página 132

WAN Top TalkersChapter 5 Using Observer with a WAN Probe86rev. 1Figure 57 WAN Load by DLCI Graph ViewThe WAN Load display in graph view shows these s

Página 133 - GigaStor Portable

WAN FilteringChapter 5 Using Observer with a WAN Probe87rev. 1second, etc.) that apply to WAN is a subset of those available for standard network anal

Página 134 - Appendix C GigaStor Portable

Triggers and AlarmsChapter 5 Using Observer with a WAN Probe88rev. 1Figure 59 Active FiltersTriggers and AlarmsWAN Observer adds WAN-related criteria

Página 135

Triggers and AlarmsChapter 5 Using Observer with a WAN Probe89rev. 1Figure 61 Probe Alarm Settings4 Select the alarms you want set.5 Click the Trigge

Página 136 - Running Observer passively

9rev. 1ContentsChapter 1: About the GigaStorGigaStor versions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 137

Triggers and AlarmsChapter 5 Using Observer with a WAN Probe90rev. 1Most WAN alarms can be set on the DTE or DCE side or both. The Committed Informati

Página 138

Chapter 6 Forensic Analysis using Snort91rev. 1C h a p t e r 6

Página 139 - Numerics

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort92rev. 1Forensic Analysis, exclusive to the GigaStor version of Obs

Página 140 - Legend: ff=Figure, t=Table

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort93rev. 1that of native Snort. When you import a set of Snort rules

Página 141

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort94rev. 1Figure 64 GigaStor Analysis Options - Forensic Analysis se

Página 142

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort95rev. 1Figure 66 GigaStor Analysis Options3 Select the profile th

Página 143

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort96rev. 1If this is the first time forensic analysis has been run, y

Página 144

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort97rev. 1Figure 69 Rules tab9 Select the boxes next to the rules yo

Página 145

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort98rev. 110 Click OK to close the Forensic Analysis Profile dialog.

Página 146

Starting Forensic Analysis using Snort rulesChapter 6 Forensic Analysis using Snort99rev. 1results, you may want to adjust preprocessor settings toeli

Comentários a estes Manuais

Sem comentários