DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
153
Table 79: Signature Parameters
Parameter
Description
Signature Name
The name of the signature, up to 29 characters.
Signature ID
(Read-only) The ID assigned to the signature by the system.
Enabled
Specifies whether the signature can be used in protection profiles.
Tracking Time
The time, in milliseconds, for measuring the Active Threshold. When a
number of packets exceeding the threshold passes through the device
within the configured Tracking Time period, the device recognizes it as an
attack.
Default: 1000
Tracking Type
Defines how the device determines which traffic to block or drop when
under attack.
Values:
•
Destination Count—Select this option when the defined attack is
destination-based—that is, the hacker is attacking a specific
destination such as a Web server, for example, Ping Floods or DDoS
attacks.
•
DHCP
•
Drop All—Select this option when each packet of the defined attack is
harmful, for example, Code Red and Nimda attacks.
•
Fragments
•
FTP Bounce
•
Land Attack
•
ncpsdcan
•
Sampling—Select this option when the defined attack is based on
sampling, that is a DoS Shield attack.
•
Source and Destination Count—Select this option when the attack
type is a source and destination-based attack—that is, the hacker is
attacking from a specific source IP to a specific destination IP
address, for example, Port Scan attacks.
•
Source Count—Select this option when the defined attack is source-
based—that is, the attack can be recognized by its source address,
for example, a Horizontal Port Scan, where the hacker scans a certain
application port (TCP or UDP) to detect which servers are available in
the network.
Default: Drop All
Action Mode
The action taken when an attack is detected.
Values:
•
Drop—The packet is discarded.
•
Report Only—The packet is forwarded to the defined destination.
•
Reset Source—Sends a TCP-Reset packet to the packet source IP
address.
•
Reset Destination—Sends a TCP-Reset packet to the destination
address.
•
Reset Bidirectional—Sends a TCP-Reset packet to both the packet
source IP and the packet destination IP address.
Default: Drop
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...