Centralized Firewall Management Administration Guide

Table of Contents

Configuring Events Settings

In the Settings screen, you can now view the EVENTS tab and change the priority of the event based on their severity. The alerts and notifications can be customized and change the way they display in the Notification center or alert.

When enabled, a notification or alert is triggered in a event level.

It is recommended to upgrade to the latest firmware for the alerts to be triggered. For more information, refer to Upgrading Firmware.

Category

Device Management Interfaces

Device Physical Interfaces status whether it is up or down.

You can define a threshold value for specific interfaces to monitor their status. If an interface remains down beyond the defined threshold value, an alert will be generated. For more information, refer to Interface Status Change Alert Notifications.

License Alerts the user when any of the previously activated firewall security services or Firewall Management licenses are expiring.
Product Lifecycle

Alerts when Last Order Day and End of Support details are available for a product.

This option is available only for Gen 6 products whose Support and End-of-Life is announced. For more information, refer to Product Lifecycle.

CSE Connector Alerts about the Tunnels status, All tunnels are down, up, or some tunnels are down.
Hardware operating conditions Alerts when there is a hardware failure with Fan, power supply, network cards reset, and system disk status.
Health Status

Alerts when a device is disconnected with Firewall Management or a local change is made to the firewall outside of Firewall Management, and when device goes into Out of Sync state. It also alerts for device configuration auto synchronization.

You can define a threshold value to monitor the connection between Firewall Management and Firewall. For more information, refer to Device Status Change Alert Notifications .

HA Failover Alerts if a primary or a secondary device fails or in the case of a failover.
Firmware Alerts when there is a new firmware version available and if a firmware upgrade fails or applied successfully to the firewall.
Configuration Commit Status Alerts when a new firewall configuration commit from Firewall Management fails on the firewall or successfully applied.
Backup Status Alerts when TSR or EXP backups fail for both scheduled and on‑demand backup operations.
User Authentication

Alerts when the user logs in and logs out.

You can see the TOTP alerts when any authentication happened with TOTP Scratch Code and TOTP has been bound or unbound. For more information, refer to Configuring for TOTP Authentication Events.

Firewall Management Firewall Management Health Status

Alerts when Firewall Management is down or is not accessible for any reason.

The table on the EVENTS page displays:

Term Definition
CATEGORY / EVENTS The events are displayed in a category. Expand each category to view the associated events.
COLOR This helps color code the events in the Events page.
ID Unique ID of the event. You can use this ID to search for a particular event in the Filter.
PRIORITY Priority of the event. Expand each event and choose an option from the drop down. The available priorities are Emergency, Alert, Critical, Error, Warning, Notice, Inform, Debug, Mixed.
GUI Choose to enable or disable the event to be displayed in the graphical user interface (GUI) under Notification center. Toggle each event to enable or disable the notification. If you check the box at the category level, it gets disabled for all the events listed under the category.
ALERT

Choose to alert and send the notifications in the group.

SMS

When enabled, an SMS is sent to the registered phone number of the user in the tenant. To view the contact information, refer to Users.

Only enabling the SMS settings will not deliver the SMS. SMS notifications require a valid Twilio configuration set up by the customer. Refer Configuring Twilio Setting for SMS to configure twilio.

EMAIL Choose this option to receive notifications through email.
SYSLOG

You can configure the syslog information by clicking the SYSLOG tab on the top. Enter the Syslog Server IP and Port and click Accept.

Other functionalities on this page includes:

  • Expand All - Expands all the categories and displays the events.
  • Reset - Resets all the alerts and notifications to default settings.
  • Refresh - Refreshes the information.
  • Accept - After you make any changes to the notifications, click Accept to save them.
  • Filter - Lets you to filter the events by name, priority, ID.