Sangfor NGAF Security Report

AimanHakim Lv2Posted 30 Oct 2023 12:26

Last edited by AimanHakim 30 Oct 2023 12:26.

Hi guys,

I've a question regarding the NGAF security report. I've been told that Sangfor NGAF has the feature to generate a security report. In it contains such as attack events, server attacks and etc. Here are the details what is supposed in the reporting:

So here's an example of the security report generated regarding the server security:

Based on the report, these Target Servers should be actual servers in a network. When confront with user he said that these IP's are not servers. So now I'm really confused.

For the policy security, I've not clarify any business asset security. Untrust is the WAN, trust is the LAN. Here's my configuration:

So here's my questions:
1. Is the report was innacurate due to my configurations? Due to I've not clarified the business assests (server's IP) but instead clarify the correct zone and the IP range to all on both WAN and LAN.

2. If it's not, does that mean that the NGAF have mislabeled the server's IP with something else due to what exactly?If possible can anyone explain on how the NGAF like know which is end user's IP or server's or etc if the policy is not configured specifically pointing to either server or end users.

3. For the configurations in the security policy, what's the difference between the Source is processed via SNAT or CDN and Source not processed via SNAT or CDN in the server scenario? When to use either one options?

By solving this question, you may help 715 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

I Can Help:

Change

Moderator on This Board

1
131
3

Started Topics

Followers

Follow

18
8
0

Started Topics

Followers

Follow

Board Leaders