Sorry but I am struggling a bit with logging, either I am doing something wrong or it's just rubbish.
I have defined an explicit policy rule to drop all outbound traffic coming from a single IP address, I know it works because the client goes off-line, I have enabled logging on the rule, I want to see in the logs what traffic from that client is being dropped. I don't seem to be able to find this. Web filter logs show which URL's are being denied, but what about all the other non-web traffic, e.g. DNS or generic TCP/UDP connections? Security policy just shows the rule being hit, IPS shows some stuff but not sure if it's showing everything as it seems to be reliant on signatures.
I just want one place where I can see all the ports/protocols that are being dropped, why is it so hard to see this? Am I missing something?
Cheers,
Paul
This thread was automatically locked due to age.