Intrusion Detection System (IDS)
75
Models 2603, 2621, and 2635 User Manual
7
• Security
To enable the FTP data channel, add a trigger to open a secondary channel only when data is being passed.
This minimizes the number of open ports. Each open port is a security risk.
1.
From the Configuration Menu, > Configuration > Security >
Security Trigger Configuration...
>
New Trig-
ger
.
2.
Set the parameters as follows (See
figure 52
.):
– Transport Type = tcp
– Port Number Start = 21
– Port Number End = 21
– Allow Multiple Hosts = Block
– Max Activity Interval = 3000
– Enable Session Chaining = Block
– Enable UDP Session Chaining = Block
– Binary Address Replacement = Block
– Address Translation Type = none
3.
Click on Create.
Figure 52. Adding trigger for FTP data transfer
You should now be able to use FTP commands to pass data between Remote and Local.
Intrusion Detection System (IDS)
The security feature in the OnSite Router provides protection from a number of attacks. Some attacks cause a
host to be blacklisted (i.e., no traffic from that host is accepted under any circumstances) for a period of time.
Other attacks are simply logged. The subsequent table is a summary of the attacks detected.
Attack Name
Protocol Attacking Host Blacklisted?
Ascend Kill
UDP
yes
Echo/Chargen
UDP
no
Echo Scan
UDP
yes
Содержание OnSite 2603
Страница 23: ...23 Chapter 2 Product Overview Chapter contents Introduction 24 Applications Overview 25...
Страница 38: ...38 Chapter 4 Ethernet LAN Port Chapter contents Introduction 39 LAN Connections 39 Ethernet Port 39...
Страница 120: ...120 Appendix C Cable Recommendations Chapter contents Ethernet Cable 121 Adapter 121...