Firewall
FirewallFirewall is a network security system used for preventing unauthorized access to or from a private network. logging monitors traffic coming into and going out of the Aruba Central-managed network and acts as an investigative resource for users to track blocked sessions within the network. The tab provides detailed summary of all blocked sessions in the Gateway, aggregated based on source IP, destination IP, destination port, and protocol. It also logs the blocked sessions which are sent from the Gateways connected in the network. It allows you to audit, verify, and analyze the effects of your firewall rules. You can also analyze the sessions by using the chart displayed in the pane. The historical firewall activity with blocked sessions are displayed for 3 hours time line.
Enabling Firewall Visibility on Gateway Config
To view the graphs on the
pane, the service must be enabled. To enable the service, complete the following steps:-
In the Network Operations app, select one of the following options:
To select a Branch Gateway group in the filter:
- Set the filter to a groups. The dashboard context for a group is displayed.
-
Under
, click .The dashboard context for the gateway is displayed.
To select a Branch Gateway in the filter:
- Set the filter to .
-
Under
, click .A list of gateways is displayed in the
view. - Click a gateway under
The dashboard context for the gateway is displayed.
. - Under , click .
- Click the icon. The gateway configuration page is displayed.
- Click .
- Click . The page is displayed.
- In the page, click arrow and select the check box to enable the service.
- Click .
Firewall Dashboard
The Aruba Central:
dashboard provides a graphical and tabular representations of all the session activities belonging to Gateways managed by- Graphical view displays a bar graph that represents the session activities of a gateway over time.
- Tabular view displays a tabular view that represents the in session activities of a gateway in detail.
The complete session information is summarized at the gateway level and then enriched at Central before displaying it on the dashboard. Enrichments include client (endpoint connected wired or wireless to the network), associated network segment, application details including application category, uplink information (outbound connection used), and policy information. All session activities are scoped by time and space. From a time perspective, the dashboard displays session activities covering up to 3 hours of historical data. From a space point of view, it covers the global customer-managed network level and specific gateway level.
The session entries that are denied access are displayed in the dashboard to help network administrators understand the reason for a session being denied or blocked due to a policy.
The reason for a session being blocked could be due to one or many of the following policies being configured and enabled:
- IP Reputation
- Geographical location-based policies
- Application Reputation
- Application Classification
- Content in the web site or application
- Missed classifications and the traditional network
- Session and role access control lists
Viewing blocked Sessions in Chart View
To view the Blocked Session in chart view, complete the following steps:
-
In the Network Operations app, select one of the following options:
To select all devices, set the filter to
. The dashboard context for the global filter is displayed.To select a Branch Gateway in the filter:
- Set the filter to .
- Under , click . A list of gateways is displayed in the view.
- Click a gateway under . The dashboard context for the gateway is displayed.
-
Under
, click tab.
If the filter is set to global, then the Blocked Sessions section displays a bar indicating the blocked sessions in the following charts:
- —The histograms in this chart displays blocked sessions over time for a gateway. On hovering over histograms chart, you can view the number of blocked sessions with time range.
- —The chart displays top 10 gateways with most blocked sessions for selected time scope. On hovering over a horizontal bar, it displays the number of blocked sessions count for each gateway. Click a horizontal bar to drilldown to a particular gateway in blocked sessions table.
Viewing Blocked Sessions in tabular view
To view Blocked Sessions in tabular view for a device, click the
icon in the top right corner of Firewall page. The Blocked sessions are displayed in tabular view with the following columns:
Data Pane Item |
Description |
|
Displays the aggregated sessions. |
|
Displays last aggregated session’s timestamp. |
|
Displays MACMedia Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address of the device. Click client MAC address hyperlink to view the corresponding client Summary page. |
|
—Displays IP address of client device that initiated this session. |
|
—Displays destination IP address of this session. —Displays destination port. |
|
Displays communication protocol used. |
|
Displays application identified for this session. This column may show empty if the session is denied prior to application classification. |
|
Displays derived domain of the destination application or URLUniform Resource Locator. URL is a global address used for locating web resources on the Internet.. |
|
Displays application category. This column may show empty if the session is denied prior to app categorization. |
|
Displays WebCC category. |
|
Displays the VLANVirtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. associated with the initiating client device session. |
|
—Determines the user's network privileges based on the assigned user role. —Indicates the assigned rule. On hovering over the access rule for any session, displays the , , and applied for that session. —Indicates the policies assigned to the users. |
|
Adjusts the column width of table to fit the page evenly. |
|
Resets the table view to default columns. |