DefensePro User Guide
Basic Device Configuration
72
Document ID: RDWR-DP-V0602_UG1201
•
Configuring the Device Event Scheduler, page 91
•
Configuring Tunneling Inspection, page 92
Configuring Advanced Settings
The advanced settings comprise the following parameters:
•
Accept Weak SSL Ciphers
•
Enable Overload Mechanism
•
SRP Management Host IP Address
The Overload Mechanism—that is, the overload-protection mechanism—identifies and reports
overload conditions, and acts to reduce operations with high resource consumption.
DefensePro device uses the overload-protection mechanism to prevent the following:
•
SME Overload—When the overload occurs in the string-matching engine (SME), the
accelerator reduces the number of new sessions sent to the SME. The existing sessions continue
to pass through the SME and are inspected. Features that require the SME, including some of
the attack signatures, will not be applied to some of the sessions.
•
Master Overload—When the overload occurs in the Master CPU, only a percentage of the
traffic is processed by the CPU. Behavioral DoS footprint analysis is done on sampled data,
ensuring the continuation of the feature, but SYN Protection does not work.
•
Accelerator Overload—When the overload occurs in the Accelerator CPU, only a percentage of
the traffic is inspected, while the rest passes through using bypass modes. Inspected traffic is
passed to the Master and SME if they are not overloaded.
•
System Wide Overload—If all offload operations have failed to prevent overloaded conditions,
then a full bypass is implemented. Every device application is bypassed, including Bandwidth
Management, Statistics, Security, and so on.
To configure advanced settings
1. In the Configuration perspective Advanced Parameters tab navigation pane, select Advanced
Parameters.
2. Configure the overload mechanism and SRP parameters; and then, click
(Submit) to submit
the changes.
Table 20: Advanced Settings Parameters
Parameter
Description
Accept Weak SSL Ciphers
Specifies whether the device allows management connections over
secure protocols with ciphers shorter than 128 bits.
Default: Enabled
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...