9
Step 7: How to inform users that they have been blocked
Provides opons for how Norman Network Protecon should nofy users that are
blocked from a network path. (This opon applies only to HTTP trac).
• Display the text below.
Insert the text you want to display to the users and use HTML-tags to format the text.
• Redirect to a customized HTML page on a reachable web server.
Provides, for example, the opon of redirecng users to an HTML page on an internal
web server. This enables you to create a very specic HTML page where the design,
layout and text can be customized to your company colors and logo.
Step 8: Handling messages
Provides the opon of sending e-mail messages about selected events.
• Enable e-mail messages
Forward messages as e-mail.
Mail recipients
Enter the e-mail addresses for the nocaon recipients.
• Click Add to enter the e-mail address for a recipient.
• Select an address from the list and click Remove selected to delete an exisng
address
SMTP server sengs
The SMTP server address, name or IP-address, for the e-mail server recipient of the
SMTP message.
Note:
If you insert the SMTP server name make sure that DNS sengs are veried for the
installed operang system. Otherwise please use the IP-address.
Port
The default SMTP port is 25, which is the correct value unless you explicitly have
selected another port.
Reply-to address
Enter the e-mail address that a recipient can reply to, for example the system admin-
istrator.
Mail message body
Subject
The tle of the e-mail, for example “Message from NNP”.
Common appended text
Enter the text to include as the default e-mail footnote text.
Step 9: Seng Internet Update opons
Step 9: Seng Internet Update opons
Norman Internet Update will keep your denion les and sanner engine up to date.
The opons for automac updates are:
Update manually
Norman Internet Update will never run. All updates must be done manually with the
Update now opon.
Automac update at set intervals
Update intervals: 6 hours, 12 hours, 1 day.
Note:
It is recommended to set the Automac update interval to 6 hours.
Step 10: Reviewing the conguraon
Once the setup wizard is done, Norman Network Protecon is ready for use!
Connecng Norman Network Appliance to your network
Connect the interface named “Eth1” to the inside of your network, and the interface
named “Eth2” to the outside of your network, based on the network scenario you
selected in chapter 5.
Note:
Remember to schedule this installaon to a me of day when interrupted network
connecons can be accepted.
Username and password default sengs
User: admin
Password: admin
Step 1: Start the setup wizard
Step 2: Restricng access to the web interface
You can restrict access to the Norman Network Protecon web-interface either to
single IP-addresses or subnets. The syntax for entering IP-addresses is:
192.168.0.4/255.255.255.0
This entry will accept access from the single IP-address 192.168.0.4
192.168.0.0/255.255.255.0
This entry will accept access from the enre subnet 192.168.0.0
Step 3: Providing the license key
The license key enables Network Protecon to be updated with signature and scan-
ner engine updates. The license key is provided to you by your local vendor. If a li-
cense key was not included when you purchased Network Protecon, please contact
your local vendor or your local Norman oce.
Step 4: Conguring Network Protecon operaon mode
These seng will determine how NNP will operate. Please select the preferred
mode.
Log only
This opon will detect and log malware, but will not block it. Please use with cauon.
Bypass
This opon allows all trac to be transferred through Norman Network Protecon
without being scanned. Using this opon will result in no trac or incident stascs.
Block
This opon will eecvely block all trac from being transferred through Norman
Network Protecon. This opon is known as the “Panic buon”.
Note:
Please use this opon with care as absolutely all trac in the segment/network
where Network Protecon Appliance is installed will be blocked.
Scan
This is the most used opon. By selecng this opon all trac on supported proto-
cols will be scanned for malware.
Sites blocked will be blocked for
The period for which a URL is blocked can be changed with this opon. The default
value is 1 week. Select the desired value for the period a blocked URL/Path should
remain blocked.
Note: This value can also be changed individually per blocked URL in the “Blocked
URL” menu.
Max. le size for scanning
This opon allows you to change the default limit for the le sizes Network Protec-
on Appliance should scan. The default value is 32MB. All les larger than the set
value will not be scanned.
Block les larger than max size
Check this opon to block les that are larger than the maximum allowed lesize.
Step 5: Conguring protocol scanning opons
These sengs decides how each protocol is handled. If you are not sure which scan
seng to use for a certain protocol, set it to bypass for now. You can always change
the scan sengs later.
Note: Please set all protocols to “Bypass” before connecng the appliance to the net-
work. When the appliance is connected to your network you can make the necessary
changes for each protocol.
Protocol scanning opons
Bypass Trac on this protocol will pass through without being scanned.
Block Trac on this protocol will not be allowed through NNP.
Minimal Scan Trac will be scanned using tradional signature scanning.
Archive les are not scanned.
Sandbox is not used.
Medium scan Trac will be scanned using tradional signature scanning.
Archive les are scanned.
Sandbox is not used.
Sandbox scan Trac will be scanned using tradional signature scanning.
Archive les are not scanned.
Sandbox is used.
Full Scan Trac will be scanned using tradional signature scanning.
Archive les are scanned.
Sandbox is used.
Step 6: Selecng logging opons
Provides opons for enabling and handling Norman Network Protecon logs. The
main logs are the Trac log and the Incident logs. These log opons only aect the
Trac log.
• Enable logging/stascs
Select this opon to log all trac, meaning all connecons transferred through Nor-
man Network Protecon are logged to a le. If not selected this opon disables all
trac stascs.
• Log only supported protocols
Select this opon to reduce the number of log entries. Only supported protocols
are logged, and all other connecons are disregarded. The supported protocols are:
HTTP, FTP, SMTP, POP3, TFTP, RPC, IRC, CIFS/SMB
Example:
If this opon is selected and a computer creates a connecon to a Citrix server, this
will not be visible in the log because the ICA protocol is not supported for scan.
• Purge logs older than:
Provides an opon to delete logs that are older than the value selected. This func-
onality can prevent your hard drive from being lled up with legacy logs.
Note:
Even though trac logs are purged aer 1 or 60 days, trac stascs will sll be
available in the management interface. Norman Network Protecon stores digests of
all logs, enabling a digest trac stascs, all the way back to the installaon of Nor-
man Network Protecon in your network.