DefensePro User Guide
Security Configuration
126
Document ID: RDWR-DP-V0602_UG1201
To configure early blocking for BDoS
1. In the Configuration perspective Security Settings tab navigation pane, select
BDoS Protection > Early Blocking.
2. To modify a protection type for early blocking, double-click the row.
3. Configure the parameters; and then, click OK.
Selecting Packet Header Fields for Early Blocking of DoS Traffic
You can select specific packet header fields be included in the set of specific packet headers that
DefensePro must detect to generate a footprint and start early blocking.
To select packet header fields for early blocking
1. In the Configuration perspective Security Settings tab navigation pane, select BDoS
Protection > Packet Header.
2. Select the protection type and click Go. The BDoS Packet Header table displays the relevant
packet header fields.
3. To change the early blocking enabling setting for a field, double-click the row, change the setting
in the dialog box, and click OK.
Table 59: Early Blocking Parameters
Parameter
Description
Protection Type
(Read-only) The protection for which you are configuring early
blocking.
Any Packet Header Field
When selected, DefensePro blocks DoS traffic early based on the
specified number of packet-header fields and number of packet-
header-field values thresholds.
Clear the selection to use specific packet header fields that you select
in the BDoS Packet Header table.
Any Packet Header Field
Threshold
The number of anomalous packet-header fields that DefensePro must
detect to generate a footprint and start early blocking.
Values: 1–20
Default (per protection): ICMP—17, IGMP—16, TCP-ACK-FIN—17,
TCP-FRAG—17, TCP-RST—17, TCP-SYN—17, TCP-SYN-ACK—17,
UDP—20.
Packet Header Field Values
The number of anomalous packet-header-field values that
DefensePro must detect to generate a footprint and start early
blocking.
The number of packet-header-field values must not be less than the
specified packet-header field threshold.
Values: 1–1000
Default 500
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...