DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
139
To enable DNS Flood Protection and configure global settings
1. In the Configuration perspective Security Settings tab navigation pane, select DNS Flood
Protection.
2. Configure the parameters; and then, click
(Submit) to submit the changes.
Table 69: DNS Flood Protection Global Parameters
Parameter
Description
Basic Parameters
Enable DNS Flood Protection Specifies whether DNS Flood Protection is enabled.
Note:
Changing the setting of this parameter requires a reboot to
take effect.
Learning Response Period
The initial period from which baselines are primarily weighted.
The default and recommended learning response period is one week.
If traffic rates legitimately fluctuate (for example, TCP or UDP traffic
baselines change more than 50% daily), set the learning response to
one month. Use a one day period for testing purposes only.
Values: Day, Week, Month
Default: Week
Footprint Strictness
When DefensePro detects a new attack, the DNS Flood Protection
module generates an attack footprint to block the attack traffic. If
DefensePro is unable to generate a footprint that meets the footprint-
strictness condition, the device issues a notification for the attack but
does not block it. The higher the strictness, the more accurate the
footprint. However, higher strictness increases the probability that
the device cannot generate a footprint.
Values:
•
High—Enforces at least three Boolean ANDs and no other
Boolean OR value in the footprint. This level lowers the
probability for false positives but increases the probability for
false negatives.
•
Medium—Enforces at least two Boolean ANDs and no more than
two additional Boolean OR values in the footprint.
•
Low—Allows any footprint suggested by the DNS Flood Protection
module. This level achieves the best attack blocking, but
increases the probability of false positives.
Note:
Table 70 - DNS Footprint Strictness Examples, page 141
shows examples of footprint strictness requirements.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...