Firewall
156
Log results to database to use a remote analysis server. If it is left unchecked, results
are output to the device's system log (Advanced -> System Log).
The device currently only supports the MySQL Database Type.
Enter the table name of remote data in Database Name.
Enter the IP address or resolvable Hostname of the analysis server.
Enter the Database port of the analysis server. For MySQL type databases, this is
typically 3306.
Sensor Name is an arbitrary string that is prepended to the log output. This may be
useful if you have deployed more than one intrusion detection system.
Enter the Username and Password required for authentication to the remote database.
Click Submit to apply your changes.
Setting up the analysis server
Specific open source tools are required to be installed on the Analysis server for a
straightforward evaluation.
The analysis server is typically a Pentium 4 level system running Linux (Red Hat, Debian,
etc.) with sufficient memory and disk capacity to run a database and web server with at
least one Ethernet port. With these tools installed, web pages can be created that
display, analyze and graph data stored in the MySQL database from the CyberGuard SG
appliance running Advanced Instrusion Detection. They should be installed in the
following order: