Forefront UAG

Version: Forefront Unified Access Gateway 2010 and later.

Forefront UAG as a DirectAccess server, to provide a seamless connection to internal resources for client devices that are running as DirectAccess clients. Client requests are securely directed to the internal network, without requiring a VPN connection. Forefront UAG DirectAccess extends the benefits of Windows DirectAccess by providing scalability, access to IPv4 resources, and simplified deployment.

Forefront Unified Access Gateway can be configured to send the events to Netsurion Open XDR by deploying agent.

With Netsurion Open XDR, organizations have complete visibility into their IT infrastructure. Know whats happening now, what happened previously, what changed, and be compliant. Netsurion Open XDR offers a high-level view, but allows you to drill down to the most granular level and provide you with the information you need whether you are in charge of overall implementation, security, and compliance, or focused on the details of the events of specific devices.

Netsurion Data Source Integrations for Forefront Unified Access Gateway allows you to monitor following:-

  • Monitoring IP helper service settings.
  • Monitoring new control connection initiated in clientapp.
  • Monitoring OTP certificate activity
  • Monitoring network activity.
  • Monitoring user login activity.
  • Monitoring services

Once Forefront UAG is configured to deliver events to Netsurion Open XDR Manager alerts, dashboards and reports can be configured into Netsurion Open XDR.

The following are the key Data Source Integration available in Netsurion Open XDR.

Alerts

Type Name Description
Security Forefront UAG: Certificate activation failed This alert is generated when certificate activation failed.
Security Forefront UAG: Configuration changes This alert is generated when configuration changes event occurs.
Security Forefront UAG: IP helper service error This alert is generated when IP helper service error event occurs.
Security Forefront UAG: Network configuration error This alert is generated when network configuration error event occurs.
Security Forefront UAG: OTP configuration error This alert is generated when OTP configuration error event occurs.
Security Forefront UAG: User login failed This alert is generated when user login failed.

Reports

Type Name Description
Security Forefront UAG: Certificate activation failed This category based report provides information related to certificate activation failed.
Security Forefront UAG: Certificate cannot be installed This category based report provides information related to certificate cannot be installed.
Security Forefront UAG: Certificate requested This category based report provides information related to certificate requested.
Security Forefront UAG: Configuration changes This category based report provides information related to configuration changes.
Security Forefront UAG: Connection established This category based report provides information related to connection established.
Security Forefront UAG: DNS service restarted This category based report provides information related to DNS service restarted.
Security Forefront UAG: Filter shutdown This category based report provides information related to filter shutdown.
Security Forefront UAG: Filter startup This category based report provides information related to filter startup.
Security Forefront UAG: IP helper service error This category based report provides information related to IP helper service error.
Security Forefront UAG: KCD protocol transition failed This category based report provides information related to KCD protocol transition failed.
Security Forefront UAG: Network configuration error This category based report provides information related to network configuration error.
Security Forefront UAG: Network interface cannot disable This category based report provides information related to network interface cannot disable.
Security Forefront UAG: Network interface cannot enable This category based report provides information related to network interface cannot enable.
Security Forefront UAG: OTP certificate cannot be enrolled This category based report provides information related to OTP certificate cannot be enrolled.
Security Forefront UAG: OTP certificates cannot be deleted This category based report provides information related to OTP certificates cannot be deleted.
Security Forefront UAG: OTP configuration error This category based report provides information related to OTP configuration error.
Security Forefront UAG: Remote user request denied This category based report provides information related to remote user request denied.
Security Forefront UAG: Restricted URL access denied This category based report provides information related to restricted URL access denied.
Security Forefront UAG: Service down This category based report provides information related to service down.
Security Forefront UAG: Service up This category based report provides information related to service up.
Security Forefront UAG: Timeout error This category based report provides information related to timeout error.
Security Forefront UAG: Unable to send message This category based report provides information related to unable to send message.
Security Forefront UAG: Unable to start application This category based report provides information related to unable to start application.
Security Forefront UAG: URL changed This category based report provides information related to URL changed.
Security Forefront UAG: URL path not allowed This category based report provides information related to URL path not allowed.
Security Forefront UAG: User login failed This category based report provides information related to user login failed.
Security Forefront UAG: User login successful This category based report provides information related to user login successful.
Security Forefront UAG: User request denied This category based report provides information related to user request denied.