Chapter 25 Secure Policy
ZyWALL / USG (ZLD) CLI Reference Guide
175
25.4.5 ADP Add/Edit Profile Commands
These commands create or edit exsiting ADP profiles.
no bind
Removes the ADP anomaly profile’s binding.
from-zone zone_profile
Specifies the zone the traffic is coming from.
[no] activate
Turns on the ADP anomaly profile to traffic direction binding. The no
command turns it off.
idp anomaly rule { delete
<1..32> | move <1..32> to
<1..32> }
Removes or moves an ADP anomaly profile to traffic direction entry.
no idp anomaly rule <1..32>
Removes an ADP anomaly profile to traffic direction entry.
show idp anomaly rules
Displays the ADP anomaly zone to zone rules.
Table 92
ADP Zone-to-Zone Rule Commands (continued)
LABEL
DESCRIPTION
Table 93
ADP Add/Edit Profile Commands
LABEL
DESCRIPTION
idp anomaly newpro [base {all
| none}]
Creates a new IDP anomaly profile called newpro. newpro uses the
base profile you specify. Enters sub- command mode. All the following
commands relate to the new profile. Use exit to quit sub-command
mode.
description description
Use up to 60 printable ASCII characters
no description
The no command removes the descriptive name from the profile.
base {all | none}
Use the base profile you specify. You cannot change the base profile if
you specify!
scan-detection sensitivity
{low | medium | high}
Sets scan-detection sensitivity.
no scan-detection
sensitivity
Clears scan-detection sensitivity. The default sensitivity is medium.
scan-detection block-
period <1..3600>
Sets for how many seconds the ZyWALL / USG blocks all packets from
being sent to the victim (destination) of a detected anomaly attack.
[no] scan-detection {tcp-
xxx} {activate | log
[alert] | block}
Activates TCP scan detection options where {tcp-xxx} ={tcp-portscan |
tcp-portscan-fin | tcp-portscan-syn tcp-portsweep }. Also sets TCP
scan- detection logs or alerts and blocking. no deactivates TCP scan
detection, its logs, alerts or blocking.
[no] scan-detection {udp-
portscan } {activate | log
[alert] | block}
Activates or deactivates UDP port scan . Also sets UDP scan-detection
logs or alerts and blocking. no deactivates UDP scan detection, its logs,
alerts or blocking.
flood-detection block-
period <1..3600>
Sets for how many seconds the ZyWALL / USG blocks all packets from
being sent to the victim (destination) of a detected anomaly attack.
[no] flood-detection {tcp-
flood | udp-flood | icmp-
flood | igmp-flood }
{activate | log [alert] |
block}
Activates or deactivates TCP, UDP,IGMP or ICMP flood detection. Also
sets flood detection logs or alerts and blocking. no deactivates flood
detection, its logs, alerts or blocking.
[no] tcp-decoder {tcp-xxx}
activate
Activates or deactivates tcp decoder options where {tcp-xxx} = {bad-
tcp-flag | bad-tcp-l4-size | tcp-land}
tcp-decoder {tcp-xxx} log
[alert]
Sets tcp decoder log or alert options.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...