
ZyWALL IDP 10 User’s Guide
IDP Policies
6-27
Table 6-7 Configuring a User-defined IDP Policy
LABEL
DESCRIPTION
Type Select whether the policy applies to IGMP types that match (
Equal
), don’t match (
Not
Equal
), are greater than (
>
), or lesser than (
<
) the IGMP type you type in the text box
that follows.
Packet Content
Packet Content parameters are for searching packet payloads. Do a traffic packet trace
when an attack occurs and then isolate the part of the trace that identifies the attack, so
you can paste the identifying portion into the following field(s) to identify the attack.
Matching Offset
and
Matching Depth
apply to all strings. The order in which they’re
found doesn’t matter (that is string 3 could be found before string 1 as long as it’s within
the depth defined). String overlaps are also allowed.
All strings must be found to constitute a
match.
Matching Offset
Matching Offset
defines the payload start point. If
Protocol
type is
IP
, then the
matching starting point is at the end of the layer-3 header; otherwise, it starts matching
from the end of the layer-4 header.
Matching Depth
Matching Depth
the length of the payload to search for a match.
Method
Choose from
Case sensitive
(upper case and lower case letters are considered
different),
Case insensitive
(upper case and lower case letters are considered the
same),
URL string
(a complete web site address),
Hexadecimal
(0-9 and a –f
characters).
The
URL string
is case insensitive, can include the character ‘?’ and spaces and
ignores character order. Therefore “/cgi-bin/foo.exe?p1=abc&p2=def” and “/cgi-
bin/foo.exe?p2=def&p1=abc” are considered a match. Extra parameters in the payload
don’t matter either. For example, a pattern “/cgi-bin/foo.exe?p1=abc&p2=def” would
match a packet with URL string “/cgi-bin/foo.exe?p0=xyz&p1=abc&p2=def”.
Content 1~6 Type or paste the content (string or hexadecimal characters) into the corresponding
content field(s).
Apply
Click this button to save your changes back to the ZyWALL.
Cancel
Click this button to close this screen without saving any changes.
Содержание ZyXEL ZyWALL IDP 10
Страница 1: ...ZyWALL IDP 10 Intrusion Detection Prevention Appliance User s Guide Version 1 July 2004 ...
Страница 28: ......
Страница 44: ...ZyWALL IDP 10 User s Guide 5 8 Remote Management Figure 5 9 ZyWALL Command Interface Login Screen ...
Страница 45: ...IDP III P Pa ar rt t I II II I IDP This part covers configuration of the IDP Policy screens ...
Страница 46: ......
Страница 60: ...ZyWALL IDP 10 User s Guide 6 14 IDP Policies Figure 6 13 Pre defined IDP Policies Summary ...
Страница 100: ...Appendices Index VI P Pa ar rt t V VI I Appendices Index This part provides some adbanced background information on IDP ...
Страница 106: ......