Configuring Services
The default service, TCP-any, looks for SYN floods in all TCP-based traffic.
Always set the SYN Protector service value to TCP-any. Selecting individual services can
cause unpredictable interactions with other rulebases.
Setting Mode
Select the mode that indicates how IDP handles TCP traffic:
•
None
. IDP takes no action, and does not participate in the three-way handshake.
•
Relay
. IDP acts as the middleman, or relay, for the connection establishment,
performing the three-way handshake with the client host on behalf of the server.
Relay mode guarantees that the server allocates resources only to connections that
are already in an ESTABLISHED state. The relay is transparent to both the client host
and the server.
IDP receives the initial SYN packet sent by the client host and returns a SYN/ACK packet.
If the client host sends an ACK packet, IDP completes the three-way handshake and
allows the connection to move to an ESTABLISHED state. If IDP does not receive an ACK
packet from the client host, as would be the case during a SYN flood attack, IDP does
not complete the three-way handshake and the connection is not established.
•
Passive
. IDP handles the transfer of packets between the client host and the server,
but does not actively prevent the connection from being established. Instead, IDP uses
a timer to ensure that connections are established promptly, minimizing the use of
server resources. The timer IDP uses for the connection establishment is shorter than
the timer the server uses for the connection queue.
IDP transfers the SYN packet sent by the client host to the server, then transfers the
SYN/ACK packet sent by the server to the client host. If the client host sends an ACK
packet to the server before the IDP connection timer expires, the connection is established.
If the client host does not send an ACK packet to the server, as would be the case during
a SYN flood attack, the IDP connection timer expires. IDP resets the connection to free
resources on the server.
Setting Notification
You can choose to log an attack and create log records with attack information that you
can view real-time in the Log Viewer. For more critical attacks, you can also set an alert
flag to appear in the log record.
To log an attack for a rule, right-click the Notification column of the rule and select
Configure
. The Configure Notification dialog box appears.
The first time you design a security policy, you might be tempted to log all attacks and
let the policy run indefinitely. Don’t do this! Some attack objects are informational only,
and others can generate false positives and redundant logs. If you become overloaded
with data, you can miss something important. Remember that security policies that
generate too many log records are hazardous to the security of your network, as you
Copyright © 2010, Juniper Networks, Inc.
500
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Страница 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Страница 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Страница 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Страница 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Страница 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Страница 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Страница 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Страница 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Страница 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Страница 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Страница 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Страница 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Страница 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Страница 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Страница 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Страница 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Страница 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Страница 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Страница 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...