Example: Using Multiple Device Templates
In this example, you create two templates that each configure different values for the
same firewall SCREEN option for the untrust zone. The first template, DoS, sets several
values in the SCREEN options, including setting the source-based IP session threshold
limit to 128 for the untrust zone. The second template, DoS2, sets the source-based IP
session threshold limit to 256 for the untrust zone. When you apply these templates to
a device, the template with the highest priority overrides the values in the lower-priority
template.
1.
Create a template that sets SCREEN options for the untrust zone, and then apply the
template to a NetScreen-208 device running ScreenOS 5.0:
a. In the navigation tree, select
Device Templates
, click the Add icon, and then select
ScreenOS/IDP Template
. The New Device Template dialog box appears.
b. In the Info screen, enter
DoS
in the Name field.
c. In the template navigation tree, select
Network > Zone
. The Zone configuration
screen appears.
d. Click the Add icon in the Zone configuration screen and select
Pre-Defined Security
Zone — trust|untrust|dmz|global
. The Predefined Zone dialog box appears.
NOTE:
Because the untrust security zone is predefined for the device,
you must select the Predefined Security Zone option. You can select
the Security Zone or Tunnel Zone option only when adding or configuring
a user-defined zone.
e. In the General Properties screen, enter
untrust
in the Name field.
f. In the zone navigation tree, select
Screen > Denial of Service Defense
. The Denial
of Service Defense screen appears.
g. Select and configure the following options:
•
Select
Ping of Death Attack Protection
,
Teardrop Attack Protection
, and
Land
Attack Protection
.
•
Select
SYN-ACK-ACK Proxy Protection
and set the Threshold to
512
.
•
Select
Source IP Based Session Limit
and set the Threshold to
128
.
•
Select
Destination IP Based Session Limit
and set the Threshold to
4000
.
Click
OK
to save the new zone.
h. Click
OK
to save the new device template.
2.
Apply the DoS template to a device configuration for a NetScreen-208 running
ScreenOS 5.0:
205
Copyright © 2010, Juniper Networks, Inc.
Chapter 5: Configuring Devices
Содержание NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Страница 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Страница 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Страница 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Страница 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Страница 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Страница 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Страница 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Страница 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Страница 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Страница 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Страница 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Страница 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Страница 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Страница 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Страница 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Страница 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Страница 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Страница 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Страница 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...