Centralized Firewall Management Administration Guide

Table of Contents

Reporting and Analytics Best Practices

Follow these recommendations to ensure wider visibility and faster response:

  • Reboot the Firewall to Enable App-Flow Settings:

    Onboarded Firewalls to NSM/Firewall Management might require a reboot to enable the App-Flow settings in the firewall if it was not enabled already. Starting with NSM 3.1 version, firewalls do not reboot automatically after acquired into NSM/Firewall Management. However, a notification will be displayed on the firewall Inventory page if a firewall reboot is required. For more information, refer to Restarting a Firewall.

  • Reconfigure Reporting & Analytics:

    Reconfigure the Reporting & Analytics of a firewall on the Manager View | Home > Firewalls > Inventory page if the firewall flow reporting data is not displayed in the NSM/Firewall Management. For more information, refer to Reinitializing Configurations for Reporting and Analytics.

  • Configure the Default and Custom Report Rules:

    Configure the default and custom reports to get on-demand or scheduled reports on the Manager View | Home > Reports > Rules page.

    For more information, refer to:

  • Configure Alerts & Notifications Rules for Specific Firewall Events:

    Configure rules on the Firewall View | Monitor > Alerts & Notifications > Rules page to get alert notifications on specific firewall events, Network Usage, Threat, Web Activities, Geo-Location, and System Events. For more information, refer to Creating an Alert Rule.

  • Configure Logs and Alerts Rules for Events Notifications:

    Configure events settings on the Manager View | Home > Log and Alerts > Settings > Events tab to get notifications on specific firewall events like interfaces up/down, configuration changes, licenses expiry, firmware updates. For more information, refer to Configuring Events Settings.

    Events are applied globally to all managed firewalls.

  • Enable Notifications for Users:

    Ensure that the Notification is enabled for the users who are allowed to receive notification emails from NSM/Firewall Management on the Manager View | Home > CSC User > Users page. For more information, refer to Users.