Problems with alerts

From: Andy Davis (andyat_private)
Date: Sat Feb 05 2000 - 08:37:36 PST

  • Next message: Michael Borkin: "Re: DMZ design - Exchange, SQL, & DCOM"

    This is a multi-part message in MIME format.
    
    ------=_NextPart_000_0005_01BF6FF7.4F00F010
    Content-Type: text/plain;
    	charset="iso-8859-1"
    Content-Transfer-Encoding: quoted-printable
    
    I am trying to get Fiewall-1 to pop up an alert box when a certain rule =
    is brought into play, for example if anyone tries to finger the firewall =
    box I want to know about it.=20
    
    I set up a rule saying:
    
    source (not my firewall)  destination (my firewall) service (finger) =
    action (drop) track (alert) install on (gateways)
    
    In policy...properties...log and alert:
    
    Popup alert command: alertf  60 2 fwalert (i.e if someone fingers me =
    twice within 60 seconds - its the only way I know how to do it)
    
    I make sure that the system status is opened.
    
    When I try to finger the firewall the log viewer logs the fact that I =
    cannot connect with finger and says that it's an alert but the alert =
    does not pop up.
    
    Hopefully someone can help,
    
    Thanks in advance,
    
    Andy Davis.
    
    
    =20
    
    ------=_NextPart_000_0005_01BF6FF7.4F00F010
    Content-Type: text/html;
    	charset="iso-8859-1"
    Content-Transfer-Encoding: quoted-printable
    
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
    <HTML><HEAD>
    <META content=3D"text/html; charset=3Diso-8859-1" =
    http-equiv=3DContent-Type>
    <META content=3D"MSHTML 5.00.2014.210" name=3DGENERATOR>
    <STYLE></STYLE>
    </HEAD>
    <BODY bgColor=3D#ffffff>
    <DIV><FONT face=3DArial size=3D2>I am trying to get Fiewall-1 to pop up =
    an alert box=20
    when a certain rule is brought into play, for example if anyone tries to =
    finger=20
    the firewall box I want to know about it.&nbsp;</FONT></DIV>
    <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>I set up a rule saying:</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>source (not my firewall)&nbsp; =
    destination (my=20
    firewall) service (finger) action (drop) track (alert) install on=20
    (gateways)</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>In policy...properties...log and=20
    alert:</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>Popup alert command: alertf&nbsp; 60 2 =
    fwalert (i.e=20
    if someone fingers me twice within 60 seconds - its the only way I know =
    how to=20
    do it)</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>I make sure that the system status is=20
    opened.</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>When I try to finger the firewall the =
    log viewer=20
    logs the fact that I cannot connect with finger and says that it's an =
    alert but=20
    the alert does not pop up.</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>Hopefully someone can =
    help,</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>Thanks in advance,</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV><FONT face=3DArial size=3D2>Andy Davis.</FONT></DIV>
    <DIV>&nbsp;</DIV>
    <DIV>&nbsp;</DIV>
    <DIV>&nbsp;</DIV></BODY></HTML>
    
    ------=_NextPart_000_0005_01BF6FF7.4F00F010--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:02:12 PDT