Enabling IDP for a Protocol
The IDP page of the NetDefendOS web interface lists a set of protocols which can be scanned by
the IDP subsystem. Selecting any of the protocols switches on IDP scanning.
Dropping Connections or Only Logging
When IDP is enabled, the administrator has two options for how detected intrusions are dealt with:
•
Log only.
•
Log and drop connection.
The Log only option can be useful to first examine what traffic IDP would block if it was fully
enabled.
Select the Minimum Number of Protocols
It is recommended to scan the minimum number of protocols required. For example, if there is only
an SMTP server in the DMZ network, then enabling the SMTP checkbox only is recommended.
IDP scanning can consume the processing resources of the DFL-160 and it is therefore best to keep
the scanning requested to a minimum.
The Scanners Category
The Scanners IDP category is not protocol specific and is an additional precaution against attempted
connections coming from the public Internet which randomly search for hosts that will respond.
Often, these try and make connections on different port numbers that might allow access to a host.
The Worms and Malware Category
4.8. IDP Options
Chapter 4. The Firewall Menu
69
Содержание NetDefend SOHO DFL-160
Страница 11: ...1 3 The LED Indicators Chapter 1 Product Overview 11...
Страница 22: ...2 4 Console Port Connection Chapter 2 Initial Setup 22...
Страница 39: ...3 7 Dynamic DNS Settings Chapter 3 The System Menu 39...
Страница 76: ...4 10 Schedules Chapter 4 The Firewall Menu 76...
Страница 78: ...5 1 Ping Chapter 5 The Tools Menu 78...
Страница 93: ...6 11 DHCP Server Status Chapter 6 The Status Menu 93...
Страница 102: ...7 6 Technical Support Chapter 7 The Maintenance Menu 102...