DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
187
Managing the Server Protection Policy
The Server Protection policy protects servers against targeted attacks. Each rule in the policy
contains Server Protection profiles to defend a specific server against network and application
attacks. You can specify an HTTP flood profile and a Server Cracking profile for each rule. These
profiles are activated when DefensePro identifies an attack on the corresponding protected server.
Before you configure rules and profiles for the Server Protection policy, ensure that you have
enabled all the required protections and configured the corresponding global protection parameters
under the Security Settings tab.
Packet Trace
Specifies whether the DefensePro device sends attack packets to the
specified physical port.
Default: Disabled
Caution:
When this feature is enabled here, for the feature to take
effect, the global setting must be enabled (Configuration
perspective > Advanced Parameters > Security
Reporting Settings > Enable Packet Trace). In addition,
a change to this parameter takes effect only after you update
policies.
Action and Escalation
Note:
The device implements the parameters in this group box only when the Manual Triggers
option is not enabled.
Profile Action
The action that the profile takes on DNS traffic during an attack.
Values: Block & Report, Report Only
Default: Block & Report
Max allowed QPS
The maximum allowed rate of DNS queries per second, when the Manual
Triggers option is not enabled.
Values: 0–4,000,000
Default: 0
Note:
When the Manual Triggers option is enabled, the Max QPS value
specified in the Manual Triggers group box takes precedence.
Signature Rate-limit
Target
The percentage of the DNS traffic that matches the real-time signature
that the profile will not mitigate above the baseline.
Values: 0–100
Default: 0
Table 97: DNS Protection Profile Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...