Server Security 14.11 Premium - Firewall-Logs

Steven_
Steven_ W/ Alumni Posts: 20 Security Scout

Hello,

is it possible to activate any firewall-logs in ServerSecurity 14.x by PolicyManager? Like in older Versions 13.x?

The diagnostics reports contains no logs. In Older logs 13.x we can view which process start the connection.

regards

Steven

Answers

  • Vad
    Vad W/ Alumni Posts: 1,069 Cybercrime Crusader
    edited February 2021

    Hello Steven,

    All firewall logs are stored in c:\ProgramData\F-Secure\Log\Firewall\. It is possible to change the logging level in 15.X versions from PMC in Centralized management -> Logging.

    It is not possible to add any additional logs in SS 14/15 versions.


    Best regards,

    Vad


  • Vad
    Vad W/ Alumni Posts: 1,069 Cybercrime Crusader

    Hello Steven,


    All Firewall logs in 14/15 versions are located in c:\ProgramData\F-Secure\Log\Firewall\ folder.

    For 15 versions it is possible to change the logging level from PMC Centralized management -> Logging. But there is no possibility to add new logs.


    Best regards,

    Vad

  • Steven_
    Steven_ W/ Alumni Posts: 20 Security Scout

    Hello,

    thanks , we only found "blocks/event" logs in the folder but not like in older clients.

    In older clients action.log sample ...

    2021-01-01T09:56:37+01:00,info,appl control,C:\Windows\System32\svchost.exe,allow,listen,17,0.0.0.0,62851

    2021-01-01T09:56:37+01:00,info,appl control,C:\Windows\System32\svchost.exe,allow,listen,17,::,62851

    Can we activate that for newer clients that use the windows-firewall?

    regards

    Steven

  • Vad
    Vad W/ Alumni Posts: 1,069 Cybercrime Crusader

    Hello,


    No, it is not possible. Those logs were generated by F-Secure Firewall binaries, which doesn't exist in new versions.


    Best regards,

    Vad

This discussion has been closed.