322
Preventing attacks
Blocking suspicious or malicious traffic with IDS
7
Click
OK
.
8
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
9
To use the IDS/IPS policy, apply it to your VPN policies, clientless VPN connections, forward filters,
Web VPN connections, port forwarders, or network interfaces.
Related information
For further information related to this topic, see the following:
■
■
“IDS/IPS Policy Properties dialog box—General tab”
■
■
Applying IDS/IPS policies
IDS/IPS policies can be applied to any of the following:
■
VPN policies
■
Clientless VPN connections
■
Forward filters
■
Web VPN connections
■
Port forwarders
■
Network interfaces
Applying an IDS/IPS policy to any of these components provides protection against malicious traffic
passing through the security gateway. By default, no IDS/IPS policies are applied to the security
gateway components.
For information on how to apply IDS/IPS policies to any of the security gateway components, see the
following:
■
Applying IDS/IPS policies to VPN policies
■
Applying IDS/IPS policies to clientless VPN connections
■
Applying IDS/IPS policies to forward filters
■
Applying IDS/IPS policies to Web VPN connections
■
Applying IDS/IPS policies to port forwarders
■
Applying IDS/IPS policies to network interfaces
Applying IDS/IPS policies to VPN policies
VPN policies are applied to secure IPsec tunnels to ensure the integrity and security of data being
passed through a tunnel. Applying an IDS/IPS policy to a VPN policy provides detection and
prevention of malicious traffic from entering the secure IPsec tunnels.
Prerequisites
None.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...