
Settings
This table pro
vides additional information for configuring alerts and logging.
Table 3-5 Settings
Setting Guidance
SNMP alert settings SNMP is not supported in the evaluated configuration due to the inherent
weaknesses in this protocol. All SNMP alerting and monitoring functionality
can be achieved using other features of the appliance. Therefore, SNMP
features should not be enabled.
SNMP monitor
settings
SNMP is not supported in the ev
aluated configuration due to the inherent
weaknesses in this protocol. All SNMP alerting and monitoring functionality
can be achieved using other features of the appliance. Therefore, SNMP
features should not be enabled.
System log settings Extended syslog features for ArcSight and Splunk are not supported in the
evaluated configuration. Therefore, these features should not be enabled.
Logging configuration To enable generation of the audit records specified in McAfee Email Gateway
Appliance 7.0 Security Target for the TOE, configure the audit event settings
as detailed in Event log settings on page 21.
Event log settings
T
o gener
ate proper audit records for the T
OE, you must configure the relevant log settings, as shown
in the following table:
Table 3-6 Event settings
Event type Setting
type
Navigation path High severity event setting
Success or failure
in logging on to
the user interface
User
interface
settings
System | Logging, Alerting
and SNMP | Logging
Configuration | Non‑proxy
Settings | User Interface
Settings, then select Advanced
• 220000 — User logon
Success or failure
in logging on to
configuration
changes
User
interface
settings
System | Logging, Alerting
and SNMP | Logging
Configuration | Non‑
proxy
Settings | User Interface
Settings, then select Advanced
• 220009 — Applying new
configuration
• 220010 — Finished applying
new configuration
• 220011 — Configuration
changed
Identification of
virus, malware or
spyw
are
SMTP
settings
System | Logging, Alerting
and SNMP | Logging
Configuration | SMTP
Settings, then select Detection
Events | Advanced
• 180000 — Anti‑virus engine
detection
POP3
settings
System | Logging, Alerting
and SNMP | Logging
Configuration | POP3
Settings, then select Detection
Events | Advanced
• 180000 — Anti‑virus engine
detection
Maintaining a TOE configuration
Logs, alerts, and SNMP
3
McAfee
®
Email Gateway 7.0.1 Common Criteria Ev
aluated Configuration Guide
Appliances
21
Commentaires sur ces manuels