Hosts

"Real time" tab

Hosts

This grid shows all hosts detected by the firewall. Each line represents a host and lists the following data:

Name

Name of the sending host (if declared in objects) or IP address of the host (if not declared).

IP address

IP address of the host.

MAC address

MAC address of the host.

Interface

Interface to which the user belongs.
Reputation Host's reputation score
This column will only contain data when host reputation management has been enabled and the selected host is a monitored host.
Packets Number of packets exchanged by the selected host.

Bytes in

Number of bytes that have passed through the firewall from the sending host ever since the firewall started running.

Bytes out

Number of bytes that have passed through the firewall towards the sending host ever since the firewall started running.

Incoming throughput

Actual throughput of traffic sent by the source host and passing through the firewall.

Outgoing throughput

Actual throughput of traffic sent to the destination host and passing through the firewall.
Protected Indicates whether the interface on which the host was detected is a protected interface.
Continent if the See all hosts (show hosts behind unprotected interfaces) checkbox has been selected in the filter, the source continent of the external host will be displayed.
Country if the See all hosts (show hosts behind unprotected interfaces) checkbox has been selected in the filter, the source country of the external host will be displayed.
Reputation category Indicates the external host's reputation category if it has been classified.

EXAMPLE
Spam, phishing, etc.

Right-click menu

Right-clicking on the name or IP address of a host opens the following pop-up menus:

  • Search for this value in the All logs view,
  • Check usage of this host,
  • Show host details,
  • Blacklist this object (for 1 minute, 5 minutes, 30 minutes or 3 hours),
  • Copy the selected line to the clipboard,
  • Copy the current cell to the clipboard,
  • Add the host to the objects base and/or add it to a group,
  • Show host's connections: displays monitoring of Connections by filtering this host,
  • Show host reputation: displays the host's reputation history in a new window below the host grid.

Possible actions

Several search criteria can be combined. All of these criteria have to be met in order to be displayed, as the search criteria are cumulative.

This combination of search criteria can then be saved as a “filter”. Filters will then be saved in memory and can be reset in the Preferences module of the administration interface.

(Filter drop-down menu)

Select a filter to launch the corresponding search. The list will suggest filters that have been saved previously and predefined filters for certain views. Selecting the entry (New filter) allows the filter to be reinitialized by selecting the criteria selection.
Filter Click on this button to:
  • Select filter criteria (Search criterion). For the "hosts" view, the criteria are the following:
  • By address range or by IP address
  • By interface
  • If the reputation score is higher than the value specified with the cursor.
  • if the See all hosts (show hosts behind unprotected interfaces) checkbox has been selected, all hosts detected will be displayed in the table.
  • Save as a customized filter the criteria defined in the Filter panel described in the next section (Save current filter). You can save a new filter using the button "Save as" based on an existing filter or a predefined filter offered in certain Views. Once a filter has been saved, it will be automatically offered in the list of filters.
  • Delete current filter.
Reset This button cancels the action of the filter currently in use. If it is a saved customized filter, this action will not delete the filter.
Refresh This button refreshes data shown on the screen.
Export results This button makes it possible to download a file in CSV containing information from the table. Once a filter is applied, all results matching this filter will be exported.
Reset columns This button makes it possible to reinitialize column width and display only columns suggested by default the first time the host monitoring window is opened.

"FILTER ON" panel

You can add a criterion by dragging and dropping the value from the results field into the panel.

Indicates the date and time of the object's connection.
Connection Connection ID
Parent connection Some protocols may generate "child" connections (e.g. FTP) and in this case, this column will list the parent connection ID.
Communication protocol used for the connection.
User logged on to the host (if any).
IP address of the host at the source of the connection
Source name Name of the object (if any) corresponding to the source host.
MAC address of the object at the source of the connection
Number of the source port used for the connection
Source Port Name Name of the object corresponding to the source port
IP address of the host to which the connection was set up.
Destination Name Name of the object (if any) to which the connection was set up.
Number of the destination port used for the connection
Dest. Port Name Name of the object corresponding to the destination port
Name of the interface on the firewall on which the connection was set up.
Name of the destination interface used by the connection on the firewall.
Average throughput Average value of bandwidth used by the selected connection.
Number of bytes sent during the connection.
Number of bytes received during the connection.
Connection time.
Last used Time elapsed since the last packet exchange for this connection.
ID assigned by the firewall to the router used by the connection
Name of the router saved in the objects database and used by the connection
Rule type Indicates whether it is a local, global or implicit rule.
ID name of the rule that allowed the connection
This parameter indicates the status of the configuration corresponding, for example, to its initiation, establishment or closure.
Queue name Name of the QoS queue used by the connection.
Rule name If a name has been given to the filter rule through which the connection passes, this name will appear in the column.
IPS profile Displays the number of the inspection profile called up by the rule that filtered the connection.
Geolocation Displays the flag corresponding to the destination country.
Reputation category Indicates the external host's reputation category if it has been classified.
Argument Additional information for certain protocols (e.g.: HTTP).
Operation Additional information for certain protocols (e.g.: HTTP).
Select a filter to launch the corresponding search. The list will suggest filters that have been saved previously and predefined filters for certain views. Selecting the entry (New filter) allows the filter to be reinitialized by selecting the criteria selection.
Filter Click on this button to:
Reset This button cancels the action of the filter currently in use. If it is a saved customized filter, this action will not delete the filter.
Refresh This button refreshes data shown on the screen.
Export results This button makes it possible to download a file in CSV containing information from the table. Once a filter is applied, all results matching this filter will be exported.
Reset columns This button makes it possible to display only columns suggested by default when the host monitoring window is opened.
Vulnerability ID
Indicates the name of the vulnerability.
Number of hosts affected.
Indicates the severity level of the vulnerability. There are 4 levels of severity: "Low", "Moderate", "High", "Critical".
Access may be local or remote (via the network). It allows exploiting the vulnerability.
Indicates whether a workaround exists.
The alarm level associated with the discovery of this vulnerability.
The network port on which the host is vulnerable (e.g. 80 for a vulnerable web server).
Indicates the name of the vulnerable program (e.g.: lighthttpd_1.4.28)
Indicates the date on which the vulnerability was detected on the host
Additional information about the vulnerability.
Name of the application.
Application family (e.g. Web client).
Full name of the application including its version number.
Indicates the port and protocol used by the service (e.g. 80/tcp).
Indicates the name of the service (e.g.: lighthttpd)
Service Indicates the name of the service including its version number (e.g. lighthhtpd_1.4.28).
Additional information about the service detected.
Family Service family (e.g. Web server).
Unique identifier of the software program or operating system detected.
Name of the software program or operating system detected.
Family to which the detected software belongs (e.g. Operating System).
The alarm level associated with the discovery of this program.
Date and time the program or operating system was detected.
Name and version of the software program or operating system detected (e.g. Microsoft_Windows_Seven_SP1).

"Reputation history" view

This view shows in the form of graphs how the reputation of the selected host has evolved and the impact of the various criteria involved in the calculation of this score (alarms, sandboxing results and antivirus analysis).

Possible operations

Time scale

In this field, the time scale can be selected: last hour, views by day,
last 7 days and last 30 days.
  • The last hour is calculated from the minute before the current minute.
  • The view by day covers the whole day, except for the current day in which data runs up to the previous minute.
  • The last 7 and 30 days refer to the period that ended the day before at midnight.

The button allows the displayed data to be refreshed.
Display the In a view by day, this field offers a calendar allowing you to select the date.

Interactive features

Left-clicking on an indicator listed in the legend allows hiding/showing the corresponding data on the graph.

When you scroll over a curve, the value of the indicator and corresponding time appear in a tooltip.

“History” tab

This view shows in the form of graphs how the reputations of hosts have evolved (average reputation and maximum reputation).

Possible operations

Time scale

In this field, the time scale can be selected: last hour, views by day,
last 7 days and last 30 days.
  • The last hour is calculated from the minute before the current minute.
  • The view by day covers the whole day, except for the current day in which data runs up to the previous minute.
  • The last 7 and 30 days refer to the period that ended the day before at midnight.

The button allows the displayed data to be refreshed.
Display the In a view by day, this field offers a calendar allowing you to select the date.
Print This button makes it possible to display the curve in fullscreen mode in order to print it (Print button).

Interactive features

Left-clicking on an indicator listed in the legend allows hiding/showing the corresponding data on the graph.

When you scroll over a curve, the value of the indicator and corresponding time appear in a tooltip.