
DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
141
Configuring DNS Footprint Bypass
You can define footprint bypass types and values that will not be used as part of a real-time
signature. The types and values not be used in OR or in AND operations within the blocking rule
(real-time signature) even when the protection-engine suggests that the traffic is a real-time
signature candidate.
To configure DNS footprint bypass
1. In the Configuration perspective Security Settings tab navigation pane, select DNS Flood
Protection > DNS Footprint Bypass.
2. From the Footprint Bypass Controller list, select the DNS query type for which you want to
configure footprint bypass, and click Go. The table displays the bypass fields for the selected
DNS query type.
3. To edit bypass type settings, double-click the corresponding row.
4. Configure the footprint bypass parameters for the selected bypass field; and then, click OK.
Duration of Non-attack
Traffic in Anomaly or Non-
Strictness State
The time, in seconds, at which the degree of attack falls below and
stays below the hard-coded threshold in the Anomaly state or the
Non-strictness state. When the time elapses, DefensePro declares
the attack to be terminated.
Values:
•
0—DefensePro declares the attack to be terminated
immediately.
•
1–300
Default: 10
Enable DNS Protocol
Compliance Checks
(This parameter is available
only when the SDM table is
enabled.)
Specifies whether the device checks each DNS query for DNS
protocol compliance and drops the non-compliant queries.
Default: Disabled
Table 70: DNS Footprint Strictness Examples
Footprint Example
Strictness Level
Low
Medium
High
DNS Query
Yes
No
No
DNS Query AND DNS ID
Yes
Yes
No
DNS Query AND DNS ID AND Packet Size
Yes
Yes
Yes
Table 69: DNS Flood Protection Global Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...