You can configure an IPS platform to send email notifications whenever the state of the inline packet inspection process state changes. This option can be configured through the Network Security appliance CLI only.
Prerequisites
Before you configure an IPS platform for email notification when the inline packet inspection process starts or stops, perform the following prerequisite tasks:
Log in to the appliance CLI as Operator or Admin.
Use the
fenotify default timezoneCLI command in configuration mode to set the default time zone for FireEye notifications. For more information, see the Network Security System Administration Guide and the CLI Command Reference.Configure email settings for administrative events, as described in "Configuring Administrative Email Settings Using the CLI" in the Network Security User Guide.
hostname (config) # email ? auth Set authentication options for sending email autosupport Set handling of automatic support email dead-letter Configure settings for saving undeliverable emails domain Override domain from which emails appear to come mailhub Set the mail relay to be used to send emails mailhub-port Set mail port to be used to send emails notify Set handling of events and failures via email return-addr Set the username in the return address for email notifications return-host Include hostname in return address for email notifications send-test Send test email to all configured event and failure recipients ssl Configure security options for email
Procedure
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Check the email settings for administrative events by using the
show emailcommand.In the following example, email notifications for administrative events are configured to be sent to the email address
my-first.my-last@my-domain.com.hostname # show email Mail hub: 172.16.2.27 Mail hub port: 25 Domain override: www.my-domain-override.com Return address: do-not-reply Include hostname in return address: yes Current reply address: do-not-reply@my-host.www.my-domain-override.com Security mode: tls-none Verify server cert: yes Supplemental CA list: default-ca-list SMTP authentication: disabled Dead letter settings: Save dead.letter files: yes Dead letter max age: 14 days Email notification recipients: my-first.my-last@my-domain.com (all events, in detail) Autosupport emails Enabled: yes Recipient: eng-autosupport@fireeye.com Mail hub: owa.fireeye.com Security mode: tls-none Verify server cert: yes Supplemental CA list: default-ca-list SMTP authentication: disabledEnable or disable notifications when the inline packet inspection process stops. Enter one of the following forms of the
email notify eventcommand:To enable notifications when the inline packet inspection process stops, enter the email notify event command, and specify the
inline‑engine‑downparameter.To disable this notification option, you would use the
noform of the command.
The following example command enables notifications when inline packet inspection processing stops.
hostname (config) # email notify event inline-engine-downEnable or disable notifications when the inline packet inspection process starts. Enter one of the following forms of the
email notify eventcommand:To enable notifications when the inline packet inspection process starts, enter the
email notify eventcommand, and specify theinline‑engine‑upparameter.To disable this notification option, you would use the
noform of the command.hostname (config) # email notify event inline-engine-up
Save your changes.
hostname (config) # write memory