cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Former Member
Not applicable
Report Inappropriate Content
Message 1 of 6

Log specific Firewall rule

Jump to solution

I am setting up the ENS Firewall and want to log traffic for a specific rule. I found three places to configure logging (excluding debug logging) and only one of them seems to work.

1. In the Firewall catalog, there's a "Log matching traffic" box for every rule that doesn't seem to be of any use.

2. In the ENS Common Options policy, we can change the "Firewall events to log" level, but it doesn't seem to be about traffic.

3. In the Firewall Options policy, there are the "Log all blocked traffic" and "Log all allowed traffic" options. This seems to be the only way to do it.

 

Is  there an actual way that works to choose which rule logs and which one does not?

 

Thank you,

Louis-André

1 Solution

Accepted Solutions
Former Member
Not applicable
Report Inappropriate Content
Message 3 of 6

Re: Log specific Firewall rule

Jump to solution

Hi Andre

The Event Logging options (Endpoint Security Common | Options | Event Logging) are used to determine whether events are sent to ePO and/or Windows Activity Log for all ENS events generated by all modules (including Threat Prevention, ATP, Web Control, etc.).

Endpoint Security Common | Options | Event Logging ( 'Send events to McAfee ePO' Or 'Log events to Windows Event Log') are ignored for ENS Firewall rules IF  "Log matching traffic" is disabled in the ENS Firewall rules. 

The Firewall Tuning options (Endpoint Security Firewall | Option | "Log all blocked traffic" OR "Log all allowed traffic") control what gets logged in FirewallEventMonitor.log for ALL firewall rules.


View solution in original post

5 Replies

Re: Log specific Firewall rule

Jump to solution

When you create a firewall rule where a local or remote network is specified as Defined Networks, ensure at least one address is added as "Not Trusted" in Defined Networks in the Firewall Options policy if you intend the rule to not match all traffic and want it to match only a specific address(es).

Venu
Former Member
Not applicable
Report Inappropriate Content
Message 3 of 6

Re: Log specific Firewall rule

Jump to solution

Hi Andre

The Event Logging options (Endpoint Security Common | Options | Event Logging) are used to determine whether events are sent to ePO and/or Windows Activity Log for all ENS events generated by all modules (including Threat Prevention, ATP, Web Control, etc.).

Endpoint Security Common | Options | Event Logging ( 'Send events to McAfee ePO' Or 'Log events to Windows Event Log') are ignored for ENS Firewall rules IF  "Log matching traffic" is disabled in the ENS Firewall rules. 

The Firewall Tuning options (Endpoint Security Firewall | Option | "Log all blocked traffic" OR "Log all allowed traffic") control what gets logged in FirewallEventMonitor.log for ALL firewall rules.


Former Member
Not applicable
Report Inappropriate Content
Message 4 of 6

Re: Log specific Firewall rule

Jump to solution
Hi Chealey,

Thanks for clarifying things, I was looking only in the "FirewallEventMonitor.log" file, that's why I didn't see any difference for the other options.

Now, looking at the ePO threat events for my machine, it seems I have to log all firewall events in the ENS Common Options to receive events for an allow rule (considered informational). Am I right?
Former Member
Not applicable
Report Inappropriate Content
Message 5 of 6

Re: Log specific Firewall rule

Jump to solution

Yes, if you want events for allowed communication you would need to enable the "log all allowed traffic" in the ENSFW options policy. This is disabled by default as it can cause a lot of events, ultimatley filling up your database.

Former Member
Not applicable
Report Inappropriate Content
Message 6 of 6

Re: Log specific Firewall rule

Jump to solution
Thank you for the information. I will do without these logs in that case.
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community