DefensePro User Guide
Basic Device Configuration
Document ID: RDWR-DP-V0602_UG1201
87
Configuring Out-of-Path Settings for DefensePro
When you install DefensePro outside the critical path of the traffic, you can configure the Out-of-Path
Mode to mitigate DoS attacks using the capabilities of the router’s access list. When the device
operates in the Out-of-Path mode, the traffic is copied to the device and verified separately from the
main traffic route. When an attack is identified, Behavioral DoS translates the footprint into a router
Access List (ACL) command and configures the router accordingly.
Note:
The feature works on Cisco routers that have the capability to mirror an interface and
accept ACL commands to reroute traffic. This feature was tested on Cisco 6509
IOS 12.2.
To configure out-of-path settings
1. In the Configuration perspective Advanced Parameters tab navigation pane, select Out of Path.
2. Configure the parameters; and then, click
(Submit) to submit the changes.
Agent IP Address
The IP address of the netForensics agent.
L4 Port
The port used for netForensics reporting.
Values: 1–65,535
Default: 555
Data Reporting Destinations
Destination IP Address
The target addresses for data reporting.
The table can contain up to 10 addresses. By default, when
there is room in the table, addresses are added automatically
when you add a DefensePro device to the tree in the system
pane.
To add an address, click the
(Add) button. Enter the
destination IP address; and then, click OK.
Table 30: Out of Path Parameters
Parameter
Description
Enable Out of Path
Mode
You must enable and reboot the device before you can configure out-of-
path settings.
When Out of Path is enabled, the only available protection is BDoS.
Router IP Address
The IP address of the organization router that manages all the incoming
traffic.
Router’s Enable
Password
Administrator’s password for the router.
Verify Password
Verification of password for the router.
Table 29: Security Reporting Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...