
DefensePro User Guide
Getting Started
Document ID: RDWR-DP-V0602_UG1201
47
With the Fail-Close option, traffic does not pass through when the platform is powered down. When
a pair of ports enters fail-close state, traffic is blocked and the link appears to be down (no power),
and switches connected to DefensePro detect the link as being down.
With the Fail-Open option, traffic passes through (not inspected by DefensePro) when the platform is
powered down.
When you configure a port pair to use the Fail-Open option, you cannot do the following:
•
Assign the ports into a link aggregation.
•
Use either of the ports for management purposes.
•
Configure either of the ports as a copied destination port. Configure the ports for SSL inspection.
Note:
By default, all the interfaces that support configurable failure mode—except the last
pair—are configured with the Process option for Port Operation with the failure mode set
to Fail-Open.
For network debugging or testing purposes, using CLI, you can manually force a pair of ports into
the failure state—without turning the power off or rebooting the device.
DefensePro sends appropriate notifications at the following times:
•
When the configuration of a port pair changes from Fail-Close to Fail-Open.
•
With the Fail-Open option, when:
—
A port changes status from up to down.
—
A port changes status from down to up.
For the procedure for configuring the failure mode, see
Configuring Port Pairs, page 45
.
Updating the Attack Description File
The Attack Description file contains descriptions of all the different attacks. You can view a specific
description by entering the attack name. When you first configure APSolute Vision, you should
download the latest Attack Description file to the APSolute Vision server. The file is used for real-
time and historical reports to show attack descriptions for attacks coming from DefensePro devices.
The file versions on APSolute Vision and on the DefensePro devices should be identical; Radware
recommends synchronizing regular updates of the file at regular intervals on APSolute Vision and on
the individual devices.
When you update the Attack Description file, APSolute Vision downloads the file directly from
Radware.com or from the enabled proxy file server.
To update the Attack Description file
1. Do one of the following:
—
In the Asset Management perspective system pane, select General Settings; and then, in
the content pane, select the Overview tab and click Update in the Attack Description group
box.
—
In the Asset Management perspective system pane, right-click General Settings; and then,
select Update Attack Description File.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...