User Guide

Table Of Contents
Bridge GUI Guide: Security Configuration
162
through and whether the interface is encrypted or clear, wired
or wireless:
Audit by User Interface - There are four ways an
administrator can access the Bridge:
Console - a serial connection to the chassis Console port
SSH - a Secure Shell connection to the Bridge CLI
GUI - an HTTPS (Hypertext Transfer Protocol Secure)
connection to the Bridge GUI
SNMP - Simple Network Management Protocol
transactions
Audit by Fortress Security - All remote management
connections to the Bridge must be made on one of its
Clear
Interfaces
(on which Fortress Security is Disabled) or on one
of its
Encrypted Interfaces (on which Fortress Security is
Enabled).
NOTE: The Wire-
less
interface type
does not apply to Bridg-
es without radios and
will not be present for
those models (refer to
Table 1.1 on page 3).
Audit by Interface Type - All remote management
connections must be made through either a
Wired interface
(Ethernet port) or a
Wireless interface, a BSS (Basic
Service Set) on one of the Bridge’s radios.
The Bridge handles audit event logging according to a
hierarchy of categories, ordered as shown above.
Each of the interface and Fortress security status controls for
audit event logging can be set to one of three behaviors:
Required - events originating from that interface or from an
interface with the specified Fortress security status will be
logged, provided they are not
Prohibited in a superior audit
setting.
Prohibited - events originating from that interface or from an
interface with the specified Fortress security status will not
be logged, provided they are not
Required in a superior
audit setting
Auto - events originating from that interface or from an
interface with the specified Fortress security status will be
logged according to whether they are
Prohibited or Required
in a superior setting. If all applicable superior settings are at
Auto, events will be logged according to any applicable
inferior settings.
In short, events are checked against the audit settings for
User
Interface, Fortress Security and Interface Type, in that order, and
logged according to the first applicable
Required or Prohibited
setting.
Audit logging is
Required by default for all interfaces, regardless
of user, type, or Fortress security status.
Logging/Auditing functions are available only in Advanced View.