DefensePro User Guide
Security Configuration
148
Document ID: RDWR-DP-V0602_UG1201
Web Quarantine
(This parameter is
available only in devices
with an SME.)
Specifies whether the device quarantines all outbound Web traffic from
internal hosts in the destination segment in the network policy after
matching a signature configured with Web-quarantine option enabled
(Network Protection tab > Signature Protection > Signatures > Web
Quarantine Option).
To enable this option, the value for the Direction field must be Two
Way.
Values: Enable, Disable
Default: Disable
Note:
For more information, see
Configuring Signature Protection
Configuring Web Quarantine Actions
and Quarantined Sources, page 163
.
Action
The default action for all attacks under this policy. Values:
•
Block and Report—The malicious traffic is terminated and a security
event is generated and logged.
•
Report Only—The malicious traffic is forwarded to its destination and
a security event is generated and logged.
Default: Block and Report
Note:
Signature-specific actions override the default action for the
policy.
Packet Reporting and Trace Setting
Packet Reporting
Specifies whether the device sends sampled attack packets to APSolute
Vision for offline analysis.
Default: Disabled
Caution:
When this feature is enabled here, for the feature to take
effect, the global setting must be enabled (Configuration
perspective > Advanced Parameters > Security
Reporting Settings > Enable Packet Reporting).
Packet Reporting
Configuration on Policy
Takes Precedence
Specifies whether the configuration of the Packet Reporting feature here,
on this policy rule takes precedence over the configuration of the Packet
Reporting feature in the associated profiles.
Packet Trace
Specifies whether the DefensePro device sends attack packets to the
specified physical port.
Default: Disabled
Caution:
When this feature is enabled here, for the feature to take
effect, the global setting must be enabled (Configuration
perspective > Advanced Parameters > Security
Reporting Settings > Enable Packet Trace). In addition,
a change to this parameter takes effect only after you
update policies.
Packet Trace
Configuration on Policy
Takes Precedence
Specifies whether the configuration of the Packet Trace feature here, on
this policy rule, takes precedence over the configuration of the Packet
Trace feature in the associated profiles.
Caution:
A change to this parameter takes effect only after you
update policies.
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...