3
102
AhnLab TrusGuard Installation Guide
After Installation
After completing the installation, monitor and check the policies managed byTrusGuard.
Monitor Policy
After installation, monitor the policies for at least 2 weeks, and change the policies according to the site
characteristics. To check whether the policies are working properly, check as below.
Go to
Firewall > Firewall Policy > IPv4 Policy
, and check the
HitCnt (1/7/30/60/90 days)
of each
policy. Policy with “0” count could be needless. Remove policies that will no longer be used.
To optimize the behavior rules in
IPS Policy
, two to three weeks of observation is needed. After the
observation period, seach for the following logs in TrusAnalyzer that is connected to TrusGuard,
and change the threshold and action.
Firewall Log: Search for
Log ID
UTM_IPS and check the detection list.
IPS Log: Check the
Rule ID
of behavior rules, and then search.
Note
If you need better Anti-DoS or Anti-DDoS feature, use AhnLab TrusGuard DPX. Use Self-Learning
feature to analyze the traffic and adjust the value according to the site environment.
Signatures detect known attacks. It may not be effective in responding to APT attacks. It is
recommended that you use AhnLab TrusWatcher. AhnLab TrusWatcher is a proactive APT response
platform customized for your environment.