DefensePro User Guide
Security Configuration
154
Document ID: RDWR-DP-V0602_UG1201
Suspend Action
Specifies which session traffic the device suspends for the duration of the
attack.
Values:
•
None—The suspend action is disabled for this attack.
•
Source IP—All traffic from the IP address identified as the source of
this attack, is suspended.
•
Source IP and Destination IP—Traffic from the IP address identified as
the source of this attack to the destination IP under attack, is
suspended.
•
Source IP and Destination Port—Traffic from the IP address identified
as the source of this attack to the application (destination port) under
attack, is suspended.
•
Source IP, Destination IP and Port—Traffic from the IP address
identified as the source of this attack to the destination IP and port
under attack, is suspended.
•
Source IP and Port, Destination IP and Port —Traffic from the IP
address and port identified as the source of this attack to the
destination IP and port under attack, is suspended.
Direction
The protection inspection path. The protections can inspect the incoming
traffic only, the outgoing traffic only, or both.
Values: Inbound, Outbound, Inbound & Outbound
Default: Inbound & Outbound
Activation Threshold
The maximum number of attack packets allowed in each Tracking Time
unit. Attack packets are recognized as legitimate traffic when they are
transmitted within the Tracking Time period.
When the value for Tracking Type is Drop All, the DefensePro device
ignores this parameter.
Default: 50
Drop Threshold
After an attack has been detected, the device starts dropping excessive
traffic only when this threshold is reached. This parameter is measured in
PPS.
When the value for Tracking Type is Drop All., the DefensePro device
ignores this parameter.
Default: 50
Termination Threshold
When the attack PPS rate drops below this threshold, the device changes
the attack from active mode to inactive mode.
When the value for Tracking Type is Drop All., the DefensePro device
ignores this parameter.
Default: 50
Packet Reporting
Enables the sending of sampled attack packets to APSolute Vision for
further offline analysis.
Default: Disabled
Exclude Source IP
Address
The source IP address or network whose packets the device does not
inspect.
Default: None
Table 79: Signature Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...