DefensePro User Guide
Security Configuration
144
Document ID: RDWR-DP-V0602_UG1201
Selecting Packet Header Fields for Early Blocking of DNS Traffic
You can select specific packet header fields be included in the set of specific packet headers that the
DefensePro device must detect to generate a footprint and start early blocking.
To select packet header fields for early blocking
1. In the Configuration perspective Security Settings tab navigation pane, select DNS Flood
Protection > Packet Header.
2. From the Protection Type drop-down list, select the protection type and click Go. The DNS
Packet Header table displays the relevant packet header fields.
3. To change the early blocking enabling setting for a field, double-click the row, change the setting
in the dialog box, and click OK.
Managing the Network Protection Policy
The network-protection policy protects your configured networks using protection profiles.
Individual network protection rules make up the network-protection policy. Each rule uses one or
more protection profiles that are applied on a predefined network segment. In addition, each rule
includes the action to take when an attack is detected.
There are two main types of network protections, Intrusion Preventions (see
Prevention Protections, page 144
) and Denial of Service protection (see
).
Table 73: DNS Packet Header Field Parameters
Parameter
Description
Protection Type
(Read-only) The protection for which you are configuring early
blocking.
Packet Header Field
(Read-only) The packet header field.
Enable Early Blocking
Condition
When selected, the packet header is included in the set of specific
packet headers that DefensePro must detect to generate a footprint
and start early blocking.
Table 74: Intrusion Prevention Protections
Protection
Description
Signatures
Prevents known application vulnerabilities, exploitation attempts, and
protects against known DoS/DDoS flood attacks.
Anti-Scanning
Prevents zero-day self-propagating network worms, horizontal scans,
and vertical scans.
Table 75: Denial of Service Protections
Protection
Description
Behavioral DoS
Detects and prevents zero-day DoS/DDoS flood attacks.
Connection Limit
Protects against connection flood attacks.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...