eG Monitoring
 

Measures reported by FPConnectionTest

The Cisco Firepower is typically pre-configured with the maximum number of connections it can handle - a limit that is pre-set based on the size of the network the firewall is designed to support. If the number of connections flowing through the firewall suddenly grows close to this limit, it could signal a problem condition that may require the immediate attention of the administrator! Such problems may be anything from an excessive spam to a mail server or a malicious virus attack on any application inside the network! To help administrators quickly capture such anomalous conditions and promptly investigate their reasons, the eG agent periodically runs this test. This test reports the average number of connections configuration of the firewall, if the average increasing very fast the administrators will be the first to know. This way, administrators can be proactively alerted to probable virus attacks/spams and initiate measures to protect their network from harm.

Outputs of the test: One set of results for the Cisco Firepower device that is to be monitored.

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
Average_connections Indicates the average number of connections passed through the to the Cisco Firepower per second . Connections/sec

If the average number of connections per second is increasing over a number of measurements it could be a spam attack and needs to be investigated.