Chapter 25 Secure Policy
ZyWALL / USG (ZLD) CLI Reference Guide
173
25.4 ADP Commands Overview
Anomaly Detection and Prevention (ADP) protects against anomalies based on violations of protocol
standards (RFCs – Requests for Comments) and abnormal flows such as port scans. This section
introduces ADP, anomaly profiles and applying an ADP profile to a traffic direction.
Traffic Anomalies
Traffic anomaly policies look for abnormal behavior or events such as port scanning, sweeping or
network flooding. They operate at OSI layer-2 and layer-3. Traffic anomaly policies may be updated
when you upload new firmware.
Protocol Anomalies
Protocol anomalies are packets that do not comply with the relevant RFC (Request For Comments).
Protocol anomaly detection includes:
• TCP Decoder
• UDP Decoder
• ICMP Decoder
Protocol anomaly policies may be updated when you upload new firmware.
[no] address6
address6_object
Sets the IPv6 source IP address. The
no
command sets this to
any
,
which
means all IP addresses.
[no] description
description
Sets a descriptive name (up to 64 printable ASCII characters) for a
session-limit rule. The
no
command removes the descriptive name from
the rule.
exit
Quits the sub-command mode.
[no] limit <0..8192>
Sets the limit for the number of concurrent NAT/firewall IPv6 sessions
this rule’s users or addresses can have. 0 means any.
[no] user
user_name
Sets an IPv6 session-limit rule for the specified user. The
no
command
resets the user name to the default (
any
).
any
means all users.
session-limit6 append
Enters the IPv6 session-limit sub-command mode to add a session-limit
rule to the end of the session-limit rule list.
session-limit6 delete
rule_number
Removes an IPv6 session-limit rule.
session-limit6 flush
Removes all IPv6 session-limit rules.
session-limit6 insert
rule_number
Enters the IPv6 session-limit sub-command mode to add a session-limit
rule before the specified rule number.
session-limit6 move
rule_number
to
rule_number
Moves an IPv6 session-limit to the number that you specified.
show session-limit6
Shows the IPv6 session-limit configuration.
show session-limit6 begin
rule_number
end
rule_number
Shows the settings for a range of IPv6 session-limit rules.
show session-limit6
rule_number
Shows the IPv6 session-limit rule’s settings.
show session-limit6 status
Shows the general IPv6 session-limit settings.
Table 88
Command Summary: Session Limit (continued)
COMMAND
DESCRIPTION
Summary of Contents for ZyWALL USG Series
Page 19: ...19 PART I Introduction ...
Page 20: ...20 ...
Page 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Page 39: ...39 PART II Reference ...
Page 40: ...40 ...
Page 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Page 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Page 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Page 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Page 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Page 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Page 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Page 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Page 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Page 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Page 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Page 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Page 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Page 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Page 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Page 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Page 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Page 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Page 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Page 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Page 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Page 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Page 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Page 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Page 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...