Chapter 27 Security Policy
ZyWALL USG Series User’s Guide
582
Traffic Anomalies
Traffic anomaly policies look for abnormal behavior or events such as port scanning, sweeping or
network flooding. They operate at OSI layer-2 and layer-3. Traffic anomaly policies may be updated
when you upload new firmware.
Protocol Anomalies
Protocol anomalies are packets that do not comply with the relevant RFC (Request For Comments).
Protocol anomaly detection includes:
• TCP Decoder
• UDP Decoder
• ICMP Decoder
Protocol anomaly policies may be updated when you upload new firmware.
Note: First, create an ADP profile in the In the
Configuration > Security Policy > ADP
>
Profile
screen.
Then, apply the profile to traffic originating from a specific zone in the
Configuration >
Security Policy > ADP
>
General
screen.
27.5.1 The Anomaly Detection and Prevention General Screen
Click
Configuration > Security Policy > ADP > General
to display the next screen.
Figure 409
Configuration > Security Policy > ADP > General
The following table describes the labels in this screen.
Table 208 Configuration > Security Policy > ADP > General
LABEL
DESCRIPTION
General Settings
Enable Anomaly Detection
and Prevention
Select this to enable traffic anomaly and protocol anomaly detection and
prevention.
Add
Select an entry and click
Add
to append a new row beneath the one selected. ADP
policies are applied in order (
Priority
) shown in this screen
Summary of Contents for USG110
Page 27: ...27 PART I User s Guide ...
Page 195: ...195 PART II Technical Reference ...
Page 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Page 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Page 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Page 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...