By default, the SYN Protector rulebase is only activated when the number of SYN packets
per second is greater than 1020. This number is the sum of two parameters that you can
set in the Sensor Settings Run-Time Parameters:
•
Lower SYN’s-per-second threshold below which SYN Protector will be deactivated
(the default value is 1000)
•
Upper SYN’s-per-second threshold above which SYN Protector will be activated (the
default value is 20)
Once the SYN Protector rulebase is activated, it remains active until the number of SYN
packets per second is less than the Lower SYN’s-per-second threshold (which is 1000
by default).
Adding the SYN Protector Rulebase
Before you can configure a rule in the SYN Protector rulebase, you need to add the SYN
Protector rulebase to a security policy.
1.
In the main navigation tree, select
Policies
. Open a security policy by double-clicking
the policy name in the Security Policies window or click the policy name and then
select the Edit icon.
2.
Click the Add icon in the upper right corner of the Security Policy window and select
Add SYN Protector Rulebase
to open the SYN Protector rulebase tab.
3.
Configure a SYN Protector rule by clicking the Add icon on the left side of the Security
Policy window to open a default SYN Protector rule. You can modify this rule as
needed.
Defining a Match
Specify the traffic you want IDP to monitor for SYN floods.
Configuring Source and Destination Address Objects
Set the Source Object to Any. Set the Destination Object to any address objects you want
to protect.
Configuring Services
The default service, TCP-any, looks for SYN floods in all TCP-based traffic.
Always set the SYN Protector service value to TCP-any. Selecting individual services can
cause unpredictable interactions with other rulebases.
Setting Mode
Select the mode that indicates how IDP handles TCP traffic:
•
None
. IDP takes no action, and does not participate in the three-way handshake.
Copyright © 2010, Juniper Networks, Inc.
492
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...