254
Setting/Setting Confirmation
|
5.8.5.
Intrusion Prevention System (IPS)
Set the appropriate Intrusion Prevention function contents according to the operation policy.
1.
Open the [Intrusion Prevention (IPS)] screen from [TOP]-[Security].
2.
Set the intrusion prevention function according to the security policy.
3.
Click the "Apply" button.
4.
Click the "Save" button to save the setting.
Setting Item
Description
Initial
Value
Intrusion Prevention
Configuration
Function that performs pattern matching pre-registered intrusion methods to
recognize and to prevent the attack to the network that cannot be detected
by the firewall by preventing the communication.
Enabled
Detect Mode
Configuration
Set the operation when illegal access is detected.
Block
Block unauthorized access and output logs.
Block
Log only
Output log indicating security risk has been detected and do not block
unauthorized access.
Detection Configuration Set this item to use the intrusion prevention extended function. Set whether
or not to block when the next packets are detected.
Enable Protocol
Anomaly Detection
It will compare with the protocol specified in RFC to detect whether it is
invalid or not. Check this item so that when traffic is detected as invalid, a
log message indicating the detection of the traffic is outputted.
Disabled
19
It does not block traffic as it may detect normal traffic as malicious traffic.