You’re offline. This is a read only version of the page.
Online Help Center
Search
Support
For Home
For Business
English (US)
Bahasa Indonesia (Indonesian)
Dansk (Danish)
Deutsch (German)
English (Australia)
English (US)
Español (Spanish)
Français (French)
Français Canadien
(Canadian French)
Italiano (Italian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português - Brasil
(Portuguese - Brazil)
Português - Portugal
(Portuguese - Portugal)
Svenska (Swedish)
ภาษาไทย (Thai)
Tiếng Việt (Vietnamese)
Türkçe (Turkish)
Čeština (Czech)
Ελληνικά (Greek)
Български (Bulgarian)
Русский (Russian)
עברית (Hebrew)
اللغة العربية (Arabic)
日本語 (Japanese)
简体中文
(Simplified Chinese)
繁體中文
(Traditional Chinese)
繁體中文 HK
(Traditional Chinese)
한국어 (Korean)
Cancel
This website uses cookies for website functionality and traffic analytics. Our Cookie Notice provides more information and explains how to amend your cookie settings.
Learn More
Yes, I agree
Table of Contents
The page you're looking for can't be found or is under maintenance
Try again later or go to the home page
Go to home page
Overview
SMS interfaces
SMS components and services
API
Devices
All devices
Device details
View, edit, or delete device distribution queue
Add a new device
Clone a device
Edit a device
Create or edit a device group
Manage a device
Unmanage a device
Remanage multiple devices
Replace a device
Delete a device
Member summary
Network summary
Events (all devices)
View, search for, and flush Blocked and Rate Limited Streams
View, search for, and flush Trusted Streams
View, search for, and unquarantine Quarantined Hosts
View AFC filters
System health (all devices)
Performance (all devices)
Packet statistics
CPU
Device users (all devices)
Device users actions
Traffic capture
Concurrent traffic capture
Create a new traffic capture file
Existing captures
Export a traffic capture file
Transfer traffic capture files to the SMS
Traffic capture expressions
Inspection bypass
Create or edit an inspection bypass rule
I/O module replacement – TPS (TX Series/TXE Series)
Network Configuration
Segments
Physical segments
Virtual Segment Assignments
Link-Down Synchronization
Import a profile
Edit device segment details
Edit a virtual segment
Ports
Edit ports
Resolve out-of-service mode
VLAN translation
Create or edit VLAN translation
Modules and Segments
Events
System Health (Health Stats)
Device health event entries
Health thresholds
Performance
Tier statistics
Tier statistics for the vTPS and TPS devices
Port health
Port statistics
Historical graphs
Traffic
System log
Audit log
Device configuration
Update management information
Reset IPS filters
Management network
Configure management network
Management routes
Host IP filters
Configure NAT
Services
Device settings
Configure a device for adaptive filtering
Device High Availability
Configure network HA
Performance Protection
Configure NMS settings for SNMP v2
SNMP settings
Log Configuration
Data Security – vTPS and TPS
Email server
Configure time settings (TPS devices)
TSE settings
Create sFlow® collector
Enable FIPS on an IPS device
Enable FIPS on a TPS device
Packet trace
Save all packet trace information for a device
Download all packet trace files for a device to the SMS
Import or export device configuration
Import device configuration
Export device configuration
Remote Authentication
Authentication preferences
Import an X509 certificate
Specify one or more RADIUS servers for IPS
Specify one or more TACACS+ servers for IPS
TippingPoint Operating System
Import TOS
Download TOS software
Distribute the TOS
Delete a previous TOS version
Roll back to a previous version
Snapshots
Create a new system snapshot on the device
Import a system snapshot from a file
Archive a system snapshot to the SMS
Export a system snapshot to a file
Restore from a system snapshot
Delete a system snapshot
Virtual segments
Virtual segment considerations
Create a virtual segment
Delete a virtual segment
Traffic Flow Analyzer
Segment groups
Create a segment group
Edit segment group membership
Edit the name and descriptions for a segment group member
Edit permissions for a segment group member
Advanced DDoS tasks
Advanced DDoS supported models
Advanced DDoS filter configuration
Ports
Proxy server port information
Required ports
Ports required to use the SMS client
Ports required for the SMS to manage devices
Ports required for software and security updates
Network ports required for the SMS to perform WhoIs lookups
Optional ports
SMS client ports
SMS server ports for devices
SMS server ports
SNMP ports
High Availability (HA) ports
SMS to SMS HA ports
TPS/TPS to TPS/TPS Transparent High Availability (TRHA) ports
Responder ports
Responder triggers for port availability
SMS encryption protocols, algorithms, and cipher support
Profiles
Shared settings
Action sets
Create or edit an action set
Notification contacts
Alert aggregation and the aggregation period
Services
SSL
Default inspection profile
Deployment modes
Capture additional event information
Inheritance
Create a new profile
Profile Tasks
Copy a profile
Compare profiles
Export profiles
Delete profiles
Import profiles
Import a profile
View profile details and versions
Edit profile details
Create a snapshot of a profile version
Activate a profile version
SSL Inspection policies
Working with filters
Filter components
Category settings
Adaptive filtering
Security filter exceptions and restrictions
Create or edit a security filter restriction or exception
Create or edit application filter restrictions
Search
Find a filter in search results
Search profile filters
View filter search results
Filter categories
Security filters
Application filters
Exploits
Identity theft
Reconnaissance filters
Scan and sweep filters
Security policy filters
Spyware
Virus
Vulnerabilities
Network equipment
Traffic normalization
Instant messaging
Peer-to-Peer (P2P)
Streaming media
Reputation feed
Reputation scores
Geographic filters
Any country
Inclusions and exclusions
Create or edit a Geographic filter
Reputation filters
Reputation filters table
Edit Reputation settings
Create or edit a Reputation filter
Change the precedence of a Reputation or Geographic filter (move up/down)
Delete a Reputation or Geographic filter
Create or edit Reputation filter exceptions
Create or edit domain name exceptions
Traffic Management filters
Create or edit a Traffic Management filter
Advanced DDoS
Create or edit an Advanced DDoS filter
Editing filters
Edit a filter
Edit multiple filters
Create or edit a filter exception
Filter details
Digital Vaccines
Auxiliary Digital Vaccines
Automatically download, activate, and distribute packages
Manually download, import, and activate packages
View Digital Vaccines or Auxiliary Digital Vaccines
Distribute a Digital Vaccine or Auxiliary Digital Vaccine
Uninstall an Auxiliary Digital Vaccine
Profile distribution
Distribution considerations
High priority
Distribute a profile
Multiple profiles
Distribution progress
Scheduled distributions
Create a new scheduled distribution
Digital Vaccine Toolkit Packages
Associate DV Toolkit packages with devices and profiles in the SMS
Create DV Toolkit packages
Limit access to DV Toolkit packages
DV Toolkit Packages
Import a DV Toolkit package
Activate a DV Toolkit package
Search for DV Toolkit filters
View original DV Toolkit filter names and numbers in the search results and events
View DV Toolkit details
Remove DV Toolkit packages from the device and the SMS
Deactivate a DV Toolkit package on the SMS
Uninstall a DV Toolkit package from the device
Delete a DV Toolkit package from the SMS
Reputation database
Malware filters
DGA filters
DNS response
19665: DNS: Suspicious DNS Lookup NOERROR Response (DGA)
20602: DNS: Suspicious DNS Lookup NXDOMAIN Response (DGA)
HTTP response
24119: HTTP: Suspicious HTTP Host Header HTTP Response (DGA)
Reputation database interface
Summary tab
Database summary
Activity tab
Sync progress
Tasks
View Reputation database details for distribution to device targets
Perform a full synchronization of the Reputation database
Stop a synchronization of the Reputation database
Clear obsolete distribution entries
Tag Categories
View integrated Advanced Threat Prevention data
Add or edit a Reputation tag category
Import tag categories
Export all tag categories
Delete a Reputation tag category
ThreatDV entries
Import a ThreatDV package
Reset a ThreatDV
User entries
Import entries into the Reputation database
Import user-provided entries to the Reputation database from a file
Adding user-provided entries to the Reputation database
Add a reputation entry, tag category, or tag value to the Reputation database
Exporting user-provided Reputation entries
Export a user-provided entry from the Reputation Database
Automatically remove user-provided entries
Edit database synchronization
Geographic entries
Reputation database search
Search criteria
Search results
Search for entries in the Reputation database
Edit bulk (all searched database entries)
Delete bulk (all searched database entries)
Edit a user-provided entry in the Reputation database
Edit multiple user-provided entries in the Reputation database
ThreatDV URL Lookup
View open threat intelligence - STIX/TAXII data
Install a TAXII client
Push observable objects from the TAXII client to the SMS
Vulnerability Scans (eVR)
Enable sharing CVE coverage gaps with the TMC
Import vulnerability scans
eVR scan specifications
Comment on a vulnerability scan
Show CVEs for a selected vulnerability scan
Search vulnerability scans for CVEs
View CVE search results
View CVE details
Profile tuning
Events
Inspection events
Search for Inspection events
Right-click options from the events table
Export Inspection event results
Open or edit a saved query
View event details
View event details
Edit a geographic filter
View geographic filter description
Reputation information
TMC ThreatLinQ charts and graphs
Table properties
Customize table property settings
Add a comment
Edit a comment
Tuning event filters (Inspection events)
Filter modifications
Packet trace
Packet trace options
Right-click packet trace menu options
External packet trace viewer
View the packet trace
Save packet trace files
Download packet trace files to the SMS
Configure packet trace view settings
URL Threat Analysis
Prerequisites
Configure URL Threat Analysis
URL Threat Analyzer results
Reports
Navigate the Reports workspace
Inspection reports
Reputation templates
Rate Limit templates
Device Traffic templates
Advanced DDoS templates
Executive reports templates
Traffic Analysis templates
Run a report
Run a report
Clear filters
Customize the criteria panels
Change the criteria panels that display on a report
Customize a query
Create a custom query for a report
Report results
Open a saved report
Edit result settings and permissions
Delete a saved report
Export report results
Export a report result
Report schedules
Create a new schedule
Edit an existing schedule
Delete a schedule
Templates
Report permissions
Saved reports
Create a saved report
Run a saved report
Edit a saved report
Save as a new report
All schedules
Edit a report schedule
Delete a report schedule
Administration
General administration
SMS server
SMS software
Download and install SMS software
Import and install SMS software from the TMC
SMS patches
Install an SMS patch
Roll back an SMS patch
SMS web security SSL certificate
Reset the SMS web security SSL certificate
Import a custom Web security SSL certificate
SMS certificate key
Update the SMS certificate key
View system health
View port health
View or export SMS system log messages
View or export SMS audit log messages
Authentication and authorization
Manage active sessions
Set or change a new resource group for a user account
Terminate an active session
Configure authentication
Authentication source
Edit the SMS server authentication source
Authentication configuration
Configure RADIUS authentication
Edit the RADIUS server configuration
Edit RADIUS group mapping
Configure Active Directory authentication
Edit the Active Directory server configuration
Edit Active Directory global group mapping
Import an Active Directory SSL certificate
Configure TACACS+ authentication
Edit the TACACS+ server configuration
Configure CAC authentication
Prerequisites
Import CA Certificates
Configure the Active Directory server for CAC authentication
Enable CAC authentication
Log in to the SMS using CAC authentication
Create or edit a user account
User roles and capabilities
Events
Reports
Profiles
Responder
Devices
Admin
Create or edit a user role
Create or edit a user group
Generate the API key
Certificate Management
Manage the SMS certificate password
Private key encryption status
Set up encryption
Change the certificate password
Reset the certificate password
View certificates
Import a certificate
Manage a certificate with ACME
Export a certificate
Replace a certificate
Repair a certificate
Make a private key non-exportable
Delete a certificate
View Certificate Authority (CA) certificates
Import a CA certificate
Export a CA certificate
Replace a CA certificate
Manage revocation
View Online Certificate Status Protocol (OCSP) settings
Specify an OCSP setting
View Certificate Revocation Lists (CRLs)
Configure a CRL location
View signing requests
Create a new signing request
Export a signing request
Import the certificate
Database
Working with the Admin (Database) screen
Database maintenance
Edit data retention settings
Reset data statistics
Initiate an immediate cleanup of data statistics
External database settings
Configure the SMS for external access
Configure the SMS for replication
Configure the SMS to enable restricted access
Backup and restore
Backup
Back up the SMS database
Edit a scheduled backup
Delete a scheduled backup
Restore
Restore the SMS database
Server Properties
Management
Update system information
Enable FIPS Crypto Core mode
Enable SMS services
Network
Update network interface information
Enable Network Time Protocol (NTP)
Manually set the date and time on the SMS server
Edit SMTP server settings
Configure an HTTP proxy connection
Configure DNS
NAT
Enable SMS NAT
Enable SMS per network NAT
ID Resolver
Configure, enable, and query IDResolver (A10 Networks)
SNMP
Enable SNMP requests
Configure an NMS trap destination
Syslog
Create or edit syslog notification settings
Create or edit a syslog format
Syslog log types
Syslog fields
Trend Micro TippingPoint app for Splunk
TLS
Edit TLS versions
Named resources
Create or edit a named resource
Create or edit named resource groups
Import or export named resources
Exports and archives
Export a file from the SMS exports and archives directory
Delete a file from the SMS exports and archives directory
IP address identifier
Add or edit an IP address ID
Delete an IP address ID
Change the priority order for IP address groups
User ID IP Correlation
Add the Identity Agent
Create an Identity Agent Group
Select an Identity Agent to be in a group
Enable Identity Agent group
User ID IP Correlation events
Configure a user resolver filter
Geo Locator Database
Automatically download a Geo Locator package
Download latest Geo Locator package from the TMC
Import a Geo Locator database file
Licensing
Edit notification settings
Import a license entitlement package
Licensing details
Export license details
SMS High Availability
Cluster requirements
Replication bandwidth requirements
Configure the cluster
Configure servers in different locations
Adjust the timeout values
View the cluster status
Synchronize the cluster
Swap the cluster node roles
Invoke a failover
Deactivate the active server
Disable the cluster
Apply software updates to a cluster
Troubleshooting
Collect logs
SMS out of Java Heap memory
Database errors
Service mode
SMS client dashboard
Dashboard palette
Default dashboard configuration
Dashboard gadgets
Health and Status gadgets
Task Status gadgets
Inspection Event gadgets
Event Rate gadget
Security gadgets
Reputation gadgets
Application gadgets
User gadgets
Customize the SMS dashboard
Select a dashboard theme
Change the dashboard layout
Restore dashboard defaults
Add or remove a gadget
Configure a gadget
Tools
Look up an IP address or hostname
Access the TMC
Access ThreatLinQ
Create a Logs Zip file for the SMS client or SMS server
Edit logging levels
Install or roll back a hotfix
Generate bookmark string
Look up users on LDAP
System preferences
Security
TMC information share
Device SNMP
Device communication
Dashboard
SSH client configuration
Banner message
PCAP download
Reports
Events
Responder
Before you begin
Responder settings
Import or export an active responder action script
Writing Response action scripts
DOCTYPE declaration
Package element
Example changes to packages
Elements of both action and device packages
Special scripts
Global functions
Action object
Callback object
Event
Alert
Signature
Host
Device objects
Correlation
Device
Global objects
Environ
Logger
Utility objects
Email
SshClient
Syslogger
WebClient
SNMP objects
SnmpContext
SnmpGet
SnmpGetNext
SnmpInform
SnmpSet
SnmpV1Trap
SnmpV2or3Trap
SnmpWalk
Manage manual response policies
Manage Responder through an external or third-party interface
Responder actions
Notification actions
Reputation entry actions
IPS quarantine actions
Switch actions
Create or edit response actions
Create an email response action
Move a quarantined host onto a VLAN response action
Create a NMS trap response action
Create a Reputation entry response action
Create an SNMP trap response action
Create a syslog response action
Create a web response action
Create an IPS quarantine response action
Policies
Policy initiation
Policy remediation communication (timeout)
Inclusions and exclusions
IP correlation and thresholding
Actions
IPS destinations
Default response policy
Edit the default response policy
Manual response
Initiate a manual response
New response policies
Create or edit a new response policy
Responder network devices
Auto discovery of switches
Configure auto discovery of network devices
Adding a switch
Add or edit a switch
SMS Web Management
Logging in to the SMS web management console
Threat Insights
Filter by time period
Compromised Hosts
Attacked Vulnerable Hosts
Suspicious Objects
ZDI Filter Hits
Filters for Review
Take action on a filter
Configure auto-flagging
Configure Filter Performance Correlation
Monitor all devices
Identify devices that require your attention
Switch a device into fallback mode
View or download saved reports
Download exported or archived files
View system logs
Install or upgrade the SMS client
Logging in to the SMS client
SMS Web Dashboard
Create a new widget
Privacy and Personal Data Collection Disclosure
External packet trace viewer
You can configure the Packet Trace Viewer to use:
Internal Packet Capture Viewer
An application registered with PCAP file association
External Packet Capture Viewer
Was this article helpful?
Inaccurate information
Too complex or confusing
Translation issue
Other
Submit
Table of Contents
Overview
SMS interfaces
SMS components and services
API
Devices
All devices
Device details
View, edit, or delete device distribution queue
Add a new device
Clone a device
Edit a device
Create or edit a device group
Manage a device
Unmanage a device
Remanage multiple devices
Replace a device
Delete a device
Member summary
Network summary
Events (all devices)
View, search for, and flush Blocked and Rate Limited Streams
View, search for, and flush Trusted Streams
View, search for, and unquarantine Quarantined Hosts
View AFC filters
System health (all devices)
Performance (all devices)
Packet statistics
CPU
Device users (all devices)
Device users actions
Traffic capture
Concurrent traffic capture
Create a new traffic capture file
Existing captures
Export a traffic capture file
Transfer traffic capture files to the SMS
Traffic capture expressions
Inspection bypass
Create or edit an inspection bypass rule
I/O module replacement – TPS (TX Series/TXE Series)
Network Configuration
Segments
Physical segments
Virtual Segment Assignments
Link-Down Synchronization
Import a profile
Edit device segment details
Edit a virtual segment
Ports
Edit ports
Resolve out-of-service mode
VLAN translation
Create or edit VLAN translation
Modules and Segments
Events
System Health (Health Stats)
Device health event entries
Health thresholds
Performance
Tier statistics
Tier statistics for the vTPS and TPS devices
Port health
Port statistics
Historical graphs
Traffic
System log
Audit log
Device configuration
Update management information
Reset IPS filters
Management network
Configure management network
Management routes
Host IP filters
Configure NAT
Services
Device settings
Configure a device for adaptive filtering
Device High Availability
Configure network HA
Performance Protection
Configure NMS settings for SNMP v2
SNMP settings
Log Configuration
Data Security – vTPS and TPS
Email server
Configure time settings (TPS devices)
TSE settings
Create sFlow® collector
Enable FIPS on an IPS device
Enable FIPS on a TPS device
Packet trace
Save all packet trace information for a device
Download all packet trace files for a device to the SMS
Import or export device configuration
Import device configuration
Export device configuration
Remote Authentication
Authentication preferences
Import an X509 certificate
Specify one or more RADIUS servers for IPS
Specify one or more TACACS+ servers for IPS
TippingPoint Operating System
Import TOS
Download TOS software
Distribute the TOS
Delete a previous TOS version
Roll back to a previous version
Snapshots
Create a new system snapshot on the device
Import a system snapshot from a file
Archive a system snapshot to the SMS
Export a system snapshot to a file
Restore from a system snapshot
Delete a system snapshot
Virtual segments
Virtual segment considerations
Create a virtual segment
Delete a virtual segment
Traffic Flow Analyzer
Segment groups
Create a segment group
Edit segment group membership
Edit the name and descriptions for a segment group member
Edit permissions for a segment group member
Advanced DDoS tasks
Advanced DDoS supported models
Advanced DDoS filter configuration
Ports
Proxy server port information
Required ports
Ports required to use the SMS client
Ports required for the SMS to manage devices
Ports required for software and security updates
Network ports required for the SMS to perform WhoIs lookups
Optional ports
SMS client ports
SMS server ports for devices
SMS server ports
SNMP ports
High Availability (HA) ports
SMS to SMS HA ports
TPS/TPS to TPS/TPS Transparent High Availability (TRHA) ports
Responder ports
Responder triggers for port availability
SMS encryption protocols, algorithms, and cipher support
Profiles
Shared settings
Action sets
Create or edit an action set
Notification contacts
Alert aggregation and the aggregation period
Services
SSL
Default inspection profile
Deployment modes
Capture additional event information
Inheritance
Create a new profile
Profile Tasks
Copy a profile
Compare profiles
Export profiles
Delete profiles
Import profiles
Import a profile
View profile details and versions
Edit profile details
Create a snapshot of a profile version
Activate a profile version
SSL Inspection policies
Working with filters
Filter components
Category settings
Adaptive filtering
Security filter exceptions and restrictions
Create or edit a security filter restriction or exception
Create or edit application filter restrictions
Search
Find a filter in search results
Search profile filters
View filter search results
Filter categories
Security filters
Application filters
Exploits
Identity theft
Reconnaissance filters
Scan and sweep filters
Security policy filters
Spyware
Virus
Vulnerabilities
Network equipment
Traffic normalization
Instant messaging
Peer-to-Peer (P2P)
Streaming media
Reputation feed
Reputation scores
Geographic filters
Any country
Inclusions and exclusions
Create or edit a Geographic filter
Reputation filters
Reputation filters table
Edit Reputation settings
Create or edit a Reputation filter
Change the precedence of a Reputation or Geographic filter (move up/down)
Delete a Reputation or Geographic filter
Create or edit Reputation filter exceptions
Create or edit domain name exceptions
Traffic Management filters
Create or edit a Traffic Management filter
Advanced DDoS
Create or edit an Advanced DDoS filter
Editing filters
Edit a filter
Edit multiple filters
Create or edit a filter exception
Filter details
Digital Vaccines
Auxiliary Digital Vaccines
Automatically download, activate, and distribute packages
Manually download, import, and activate packages
View Digital Vaccines or Auxiliary Digital Vaccines
Distribute a Digital Vaccine or Auxiliary Digital Vaccine
Uninstall an Auxiliary Digital Vaccine
Profile distribution
Distribution considerations
High priority
Distribute a profile
Multiple profiles
Distribution progress
Scheduled distributions
Create a new scheduled distribution
Digital Vaccine Toolkit Packages
Associate DV Toolkit packages with devices and profiles in the SMS
Create DV Toolkit packages
Limit access to DV Toolkit packages
DV Toolkit Packages
Import a DV Toolkit package
Activate a DV Toolkit package
Search for DV Toolkit filters
View original DV Toolkit filter names and numbers in the search results and events
View DV Toolkit details
Remove DV Toolkit packages from the device and the SMS
Deactivate a DV Toolkit package on the SMS
Uninstall a DV Toolkit package from the device
Delete a DV Toolkit package from the SMS
Reputation database
Malware filters
DGA filters
DNS response
19665: DNS: Suspicious DNS Lookup NOERROR Response (DGA)
20602: DNS: Suspicious DNS Lookup NXDOMAIN Response (DGA)
HTTP response
24119: HTTP: Suspicious HTTP Host Header HTTP Response (DGA)
Reputation database interface
Summary tab
Database summary
Activity tab
Sync progress
Tasks
View Reputation database details for distribution to device targets
Perform a full synchronization of the Reputation database
Stop a synchronization of the Reputation database
Clear obsolete distribution entries
Tag Categories
View integrated Advanced Threat Prevention data
Add or edit a Reputation tag category
Import tag categories
Export all tag categories
Delete a Reputation tag category
ThreatDV entries
Import a ThreatDV package
Reset a ThreatDV
User entries
Import entries into the Reputation database
Import user-provided entries to the Reputation database from a file
Adding user-provided entries to the Reputation database
Add a reputation entry, tag category, or tag value to the Reputation database
Exporting user-provided Reputation entries
Export a user-provided entry from the Reputation Database
Automatically remove user-provided entries
Edit database synchronization
Geographic entries
Reputation database search
Search criteria
Search results
Search for entries in the Reputation database
Edit bulk (all searched database entries)
Delete bulk (all searched database entries)
Edit a user-provided entry in the Reputation database
Edit multiple user-provided entries in the Reputation database
ThreatDV URL Lookup
View open threat intelligence - STIX/TAXII data
Install a TAXII client
Push observable objects from the TAXII client to the SMS
Vulnerability Scans (eVR)
Enable sharing CVE coverage gaps with the TMC
Import vulnerability scans
eVR scan specifications
Comment on a vulnerability scan
Show CVEs for a selected vulnerability scan
Search vulnerability scans for CVEs
View CVE search results
View CVE details
Profile tuning
Events
Inspection events
Search for Inspection events
Right-click options from the events table
Export Inspection event results
Open or edit a saved query
View event details
View event details
Edit a geographic filter
View geographic filter description
Reputation information
TMC ThreatLinQ charts and graphs
Table properties
Customize table property settings
Add a comment
Edit a comment
Tuning event filters (Inspection events)
Filter modifications
Packet trace
Packet trace options
Right-click packet trace menu options
External packet trace viewer
View the packet trace
Save packet trace files
Download packet trace files to the SMS
Configure packet trace view settings
URL Threat Analysis
Prerequisites
Configure URL Threat Analysis
URL Threat Analyzer results
Reports
Navigate the Reports workspace
Inspection reports
Reputation templates
Rate Limit templates
Device Traffic templates
Advanced DDoS templates
Executive reports templates
Traffic Analysis templates
Run a report
Run a report
Clear filters
Customize the criteria panels
Change the criteria panels that display on a report
Customize a query
Create a custom query for a report
Report results
Open a saved report
Edit result settings and permissions
Delete a saved report
Export report results
Export a report result
Report schedules
Create a new schedule
Edit an existing schedule
Delete a schedule
Templates
Report permissions
Saved reports
Create a saved report
Run a saved report
Edit a saved report
Save as a new report
All schedules
Edit a report schedule
Delete a report schedule
Administration
General administration
SMS server
SMS software
Download and install SMS software
Import and install SMS software from the TMC
SMS patches
Install an SMS patch
Roll back an SMS patch
SMS web security SSL certificate
Reset the SMS web security SSL certificate
Import a custom Web security SSL certificate
SMS certificate key
Update the SMS certificate key
View system health
View port health
View or export SMS system log messages
View or export SMS audit log messages
Authentication and authorization
Manage active sessions
Set or change a new resource group for a user account
Terminate an active session
Configure authentication
Authentication source
Edit the SMS server authentication source
Authentication configuration
Configure RADIUS authentication
Edit the RADIUS server configuration
Edit RADIUS group mapping
Configure Active Directory authentication
Edit the Active Directory server configuration
Edit Active Directory global group mapping
Import an Active Directory SSL certificate
Configure TACACS+ authentication
Edit the TACACS+ server configuration
Configure CAC authentication
Prerequisites
Import CA Certificates
Configure the Active Directory server for CAC authentication
Enable CAC authentication
Log in to the SMS using CAC authentication
Create or edit a user account
User roles and capabilities
Events
Reports
Profiles
Responder
Devices
Admin
Create or edit a user role
Create or edit a user group
Generate the API key
Certificate Management
Manage the SMS certificate password
Private key encryption status
Set up encryption
Change the certificate password
Reset the certificate password
View certificates
Import a certificate
Manage a certificate with ACME
Export a certificate
Replace a certificate
Repair a certificate
Make a private key non-exportable
Delete a certificate
View Certificate Authority (CA) certificates
Import a CA certificate
Export a CA certificate
Replace a CA certificate
Manage revocation
View Online Certificate Status Protocol (OCSP) settings
Specify an OCSP setting
View Certificate Revocation Lists (CRLs)
Configure a CRL location
View signing requests
Create a new signing request
Export a signing request
Import the certificate
Database
Working with the Admin (Database) screen
Database maintenance
Edit data retention settings
Reset data statistics
Initiate an immediate cleanup of data statistics
External database settings
Configure the SMS for external access
Configure the SMS for replication
Configure the SMS to enable restricted access
Backup and restore
Backup
Back up the SMS database
Edit a scheduled backup
Delete a scheduled backup
Restore
Restore the SMS database
Server Properties
Management
Update system information
Enable FIPS Crypto Core mode
Enable SMS services
Network
Update network interface information
Enable Network Time Protocol (NTP)
Manually set the date and time on the SMS server
Edit SMTP server settings
Configure an HTTP proxy connection
Configure DNS
NAT
Enable SMS NAT
Enable SMS per network NAT
ID Resolver
Configure, enable, and query IDResolver (A10 Networks)
SNMP
Enable SNMP requests
Configure an NMS trap destination
Syslog
Create or edit syslog notification settings
Create or edit a syslog format
Syslog log types
Syslog fields
Trend Micro TippingPoint app for Splunk
TLS
Edit TLS versions
Named resources
Create or edit a named resource
Create or edit named resource groups
Import or export named resources
Exports and archives
Export a file from the SMS exports and archives directory
Delete a file from the SMS exports and archives directory
IP address identifier
Add or edit an IP address ID
Delete an IP address ID
Change the priority order for IP address groups
User ID IP Correlation
Add the Identity Agent
Create an Identity Agent Group
Select an Identity Agent to be in a group
Enable Identity Agent group
User ID IP Correlation events
Configure a user resolver filter
Geo Locator Database
Automatically download a Geo Locator package
Download latest Geo Locator package from the TMC
Import a Geo Locator database file
Licensing
Edit notification settings
Import a license entitlement package
Licensing details
Export license details
SMS High Availability
Cluster requirements
Replication bandwidth requirements
Configure the cluster
Configure servers in different locations
Adjust the timeout values
View the cluster status
Synchronize the cluster
Swap the cluster node roles
Invoke a failover
Deactivate the active server
Disable the cluster
Apply software updates to a cluster
Troubleshooting
Collect logs
SMS out of Java Heap memory
Database errors
Service mode
SMS client dashboard
Dashboard palette
Default dashboard configuration
Dashboard gadgets
Health and Status gadgets
Task Status gadgets
Inspection Event gadgets
Event Rate gadget
Security gadgets
Reputation gadgets
Application gadgets
User gadgets
Customize the SMS dashboard
Select a dashboard theme
Change the dashboard layout
Restore dashboard defaults
Add or remove a gadget
Configure a gadget
Tools
Look up an IP address or hostname
Access the TMC
Access ThreatLinQ
Create a Logs Zip file for the SMS client or SMS server
Edit logging levels
Install or roll back a hotfix
Generate bookmark string
Look up users on LDAP
System preferences
Security
TMC information share
Device SNMP
Device communication
Dashboard
SSH client configuration
Banner message
PCAP download
Reports
Events
Responder
Before you begin
Responder settings
Import or export an active responder action script
Writing Response action scripts
DOCTYPE declaration
Package element
Example changes to packages
Elements of both action and device packages
Special scripts
Global functions
Action object
Callback object
Event
Alert
Signature
Host
Device objects
Correlation
Device
Global objects
Environ
Logger
Utility objects
Email
SshClient
Syslogger
WebClient
SNMP objects
SnmpContext
SnmpGet
SnmpGetNext
SnmpInform
SnmpSet
SnmpV1Trap
SnmpV2or3Trap
SnmpWalk
Manage manual response policies
Manage Responder through an external or third-party interface
Responder actions
Notification actions
Reputation entry actions
IPS quarantine actions
Switch actions
Create or edit response actions
Create an email response action
Move a quarantined host onto a VLAN response action
Create a NMS trap response action
Create a Reputation entry response action
Create an SNMP trap response action
Create a syslog response action
Create a web response action
Create an IPS quarantine response action
Policies
Policy initiation
Policy remediation communication (timeout)
Inclusions and exclusions
IP correlation and thresholding
Actions
IPS destinations
Default response policy
Edit the default response policy
Manual response
Initiate a manual response
New response policies
Create or edit a new response policy
Responder network devices
Auto discovery of switches
Configure auto discovery of network devices
Adding a switch
Add or edit a switch
SMS Web Management
Logging in to the SMS web management console
Threat Insights
Filter by time period
Compromised Hosts
Attacked Vulnerable Hosts
Suspicious Objects
ZDI Filter Hits
Filters for Review
Take action on a filter
Configure auto-flagging
Configure Filter Performance Correlation
Monitor all devices
Identify devices that require your attention
Switch a device into fallback mode
View or download saved reports
Download exported or archived files
View system logs
Install or upgrade the SMS client
Logging in to the SMS client
SMS Web Dashboard
Create a new widget
Privacy and Personal Data Collection Disclosure