The Network Security Web UI contains the following tabs.
Note
On a Network Security sensor or sensor-enabled Network Security integrated appliance, the Settings > YARA Rules and Settings > Guest Images are not displayed in the Web UI.
Tab | Description |
|---|---|
Dashboard | Overview of threat intelligence gathered by the appliance. See “The Appliance Dashboard” in the Network Security System Administration Guide. |
Alerts | Details about infected network hosts, malware attacks, and callback activity to botnet servers. |
Settings | Appliance and threat management configuration settings: Date and Time—Configure the date and time or specify one or more NTP servers. User Accounts—Manage user accounts, including passwords, role assignments, and local access status, and reset your own password if you are assigned the Admin role. Email—Configure the appliance email account used for system notifications. DTI Network—Specify the frequency of security and statistical content uploads. CMS Network—Initiate a request to be added to the Central Management System appliance. Inline Operational Modes—Configure and customize inline monitoring operations. Alert Policy Exceptions—Adjust the blocking policy for a particular event or the suppression policy for a particular rule. Whitelists—Configure three whitelists—Generic Routing Encapsulation (GRE) traffic, port, and network. Add IPs and domains to submission whitelist. Notifications—Configure and test event notifications for analysis alerts. Network—View management interface settings and configure DNS settings. YARA Rules—Upload byte-level rules that quickly analyze large quantities of files. Guest Images—View information about the currently loaded guest images (virtual machines) that test traffic and software for malicious activity. Riskware Policy—Enable the riskware detection feature. Enable policy rules based on custom riskware detection. Certificates/Keys—Upload SSL certificates. SSL Intercept—Configure SSL interception to decrypt and inspect HTTPS traffic. Port Mirroring—Configure port mirroring for all traffic types (including SSL encrypted traffic) and SSL decryption mirroring. ICAP—Integrate Internet Content Adaptation Protocol (ICAP) on the Network Security appliance. Data Retention Policy - Configure number of days to retain appliance data and schedule purging frequency. Appliance Backup & Restore—Perform back up and restore operations for the appliance database. Appliance Licenses—Install and remove licenses. Login Banner—Configure the banner text displayed when a user logs in to the appliance CLI. |
Reports | Generate or schedule consolidated executive summary reports, callback server reports, infected host trends reports, alert details reports, and malware activity reports. |
About | Network administration information and controls: Summary—Check overall status information about system health and appliance performance. Health Check— Check appliance and system health information. Deployment Check—Check connectivity to DTI services and verify detection components. Log Manager—Create, download, upload, and delete log archives. Upgrade—Check for and install new security content, appliance image, and guest images. |