Connection events are user-defined
notifications of open
connections to or from particular addresses or ports. The Network
IPS appliance generates connection events when it detects network
activity at a designated port, regardless of the type of activity,
network packet, or exchanged content.
About this task
The
Connection
Events page for the
Network IPS appliance lists predefined connection events for different
connection types, such as WWW, FTP, or IRC. Use this page to customize
these events or to create your own events to cover the traffic that
you need to monitor. For example, you can define a rule that causes
a connection event to alert the console whenever someone connects
to the network using FTP.
Note: The connections are always registered
against the destination port you specify. To monitor an FTP connection,
you must use the FTP port. One entry per connection is sufficient
for traffic in each direction.