What new features and functionality are available in Security Reporting Center 2.0?


This article applies to:

  • Security Reporting Center 2.0x

Question:

What new features and functionality are available in Security Reporting Center 2.0?

Information:

Security Reporting Center 2.0: New Features Overview

Installation Changes

Windows installation includes some minor changes to User Interface organization and some terminology changes to make it simpler. In general, it is easier to click through using the defaults.

  • You can choose not to install either the Firewall or Proxy module.

  • Windows domain authentication is no longer available.

  • User name for the UI server is now called Login Name, to make sure users know it is the same login used to access Security Reporting Center.

Usability Enhancements

Various changes have been made to help users understand basic concepts and the value of Security Reporting Center, and to make the interface and Help more navigable.

  • Sample reports are now created during installation and accessible in a single click.

  • New orientation pages assist new users with reporting tasks. (Select the Do not show Orientation Pages by default check box if you do not want to see this every time.)

  • New Help site maps, accessible from the left pane of each Help page, provide an organized list of all Help topics.

  • Module options have been reorganized for greater clarity.

Proxy Reporting Module New Features: Performance Options

The Proxy module adds URL Categorization and Web usage reports to the functionality provided by the Firewall module.  The following User Interface features are available in the Proxy module only

  • Categories panel in the Profile configuration panels. Lets you choose whether to enable categorization and whether to use a category mapping for a specific profile.

  • Proxy Reporting options focused on Web usage reporting.

  • URL Categorization options.

  • New Proxy-specific filters.

New Options Structure

  • Module options, in the left column of the Options panel, are module-specific settings.

  • Common options, in the right column of the Options panel, can be set in both Firewall and Proxy, for either module.


Module Options

Common Options

Log Analysis

Department Management

Firewall/Proxy Reporting

Syslog

URL Categorization (Proxy only)

Log File Path Macros

Global Proxy Filters

Currency Types

FastTrends Database Management

Protocols

Content Database Management

Licensing Information

Check For Update

Licensing Information

Note: Content and FastTrends database options are now located in their own categories under module-specific options.

Support for New Firewalls

With version 2.0, Security Reporting Center adds support for Arkoon Network Security, CimTrak Web Security Edition, Fortinet FortiGate Network Protection Gateways, Lucent VPN Firewall, and CyberWALLPlus.

Categorization Options (Access at Reporting Module | Options | URL Categorization)

  • General - Lets you enable and disable categorization of IP addresses, decide whether to only categorize file types defined as Web pages, and choose the location of the SurfControl URL categorization databases.

  • Custom Database - Lets you choose URLs to be tracked and categorize them in new or existing categories.

  • Third-Party Database - Lets you register, update, and check status of the SurfControl URL categorization databases.

  • Category Mapping - Lets you map individual categories to new categories such as Non-Work-Related. Mappings can be filtered or assigned to individual profiles to create customized reports.

URL Categorization Filters

There are three new filters targeted for URL Categorization: the Core Category filter, the General Category filter, and the Uncategorized Data filter. The Core and General Category filters allow you to select specific categories and category mappings, or all categories and category mappings.


Proxy-Specific Reporting Options

  • Download File Types - Lets you decide which file types are counted as downloads in reports.

  • Page File Types - Lets you decide which file types are counted as pages in reports.

  • Domains - Lets you decide which domains are tracked in reports that specify domains visited.

  • Visitor Sessions - Lets you decide when an Internet session is considered to have timed out for reporting purposes.

Other Proxy Filters

  • Site - Filters sites by address, domain, type, region, or country

  • User Address - Filters user addresses

  • File - Filters individual files or file types

  • Proxy Cache - Filters activity by proxy cache code

  • Action - Filters activity by the BLOCK or PASS action it triggers on the firewall

New Features: Performance Options

  • Content Database Table Size  - Improve performance by limiting the number of rows that can be exported to the Content database, for all tables. Access this setting at Reporting Module | Options | Firewall/Proxy Reporting | Content Database Table Size.

  • Memory Usage - Limit the memory consumed by each report table. This setting is table-specific. Access this setting at Reporting Module | Options | Firewall/Proxy Reporting | Content Database Table Size.

  • Custom FTP Handling - FTP settings, specific to each Reporting module, have been broken out into two panels.

  • Custom DNS handling - DNS handling has now been split into External and Internal DNS settings for better fine-tuning. Access this setting at Reporting Module | Options | DNS.

  • Out-of Order Record Handling - Choose how often to discard out-of-order log records. Reporting Module | Options | Log Analysis | Out-of-Order Records.

  • Host Groups - Decide which computers analyze which log files by creating custom host groups. Host groups are created in the Host Groups panel at Scheduler | Options | Host Groups. Host groups can be assigned to each profile in the profile settings, or the default for all profiles can be chosen at Reporting Module | Options | Log Analysis | Host Binding Default.


New Features: Miscellaneous Options

  • MAPI E-mail Support - Report distribution by e-mail now supports MAPI as well as SMTP. Configure e-mail settings in the E-mail Settings panel (Scheduler | Options | Global Agent Settings | E-mail Settings.) Choose e-mail delivery in the Report Destination and Parameters panel when you create an event.

  • Log Path Macros  - New support for custom macros substitutes log paths with operating system-specific variables, enabling cross-platform log path specification. Log path macros can be configured in the Log File Path Macro options at Reporting Module | Options | Log File Path Macros.

  • Local Filters  - New local filters enhance security by making custom data filters visible only to authorized users of a specific profile. Local filters are created from within the profile settings, using the Filters panel. Regular filters are now referred to as Global filters. You can transform a global filter into a local one, but not vice versa.

  • Custom Currencies  - In addition to 43 preconfigured currencies, Security Reporting Center now supports user-configured currencies in bandwidth cost reporting. You cannot edit existing currencies, but you can edit ones that have been added. Click Reporting Module | Options | Currency Types to edit currencies.

  • Proxy Server Settings - If you need to download the URL Categorization settings through a proxy server, configure the connection settings at Administration | Options | Access to Internet.

This article was previously published as:
NETIQKB14683

Last Modified 4/10/2006.
https://support.trustwave.com/kb/KnowledgebaseArticle10903.aspx