DefensePro User Guide
Security Configuration
118
Document ID: RDWR-DP-V0602_UG1201
•
Scanning and worm-propagation protection—Provides zero-day protection against self-
propagating worms, horizontal and vertical TCP and UDP scanning, and ping sweeps.
•
Connection limit—Protects against session-based attacks, such as half-open SYN attacks,
request attacks, and connection attacks.
•
Connection PPS Limit protection—Protects against attacks that use a high PPS rates on one
or several connections to flood a server.
Server protections include the following:
•
Server-cracking protection—Provides zero-day protection against application-vulnerability
scanning, brute-force, and dictionary attacks.
•
HTTP-flood protection—Mitigates zero-day HTTP page flood attacks.
Access control (ACL) policies block or allow traffic to or from specified networks, based on protocols,
applications, and other criteria.
Selecting a Device for Security Configuration
You configure a security policy in the Configuration perspective.
Before you configure a security policy, select the device in the Configuration perspective navigation
pane.
To select the device for security configuration
Select the required device in the Configuration perspective system pane.
Configuring Global Security Settings
Before you configure the Server Protection Policy or the Network Protection Policy and their
protection profiles, you must enable the protection features you want to use and configure the
global parameters for the protection features.
Note:
After a protection feature is enabled on a device, the device requires a reboot; however,
you need to reboot only once after enabling features within the same navigation branch.
Use APSolute Vision to configure the following protection features on a selected device:
•
Configuring Global Signature Protection, page 119
•
Configuring DoS Shield Protection, page 119
•
Configuring Global Behavioral DoS Protection, page 121
•
Configuring Global Anti-Scanning Protection Settings, page 127
•
Configuring Global SYN Flood Protection, page 128
•
Configuring Global Out of State Protection, page 129
•
Configuring Global HTTP Flood Protection, page 131
•
Configuring Global SIP Cracking Protection, page 132
•
Configuring Global Fraud Protection, page 133
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...