Chapter 38 IDP
ZyWALL USG Series User’s Guide
718
You could create a new ‘monitor profile’ that creates logs but all actions are disabled. Observe the logs
over time and try to eliminate the causes of the false alarms. When you’re satisfied that they have been
reduced to an acceptable level, you could then create an ‘inline profile’ whereby you configure
appropriate actions to be taken when a packet matches a signature.
Packet inspection signatures examine the contents of a packet for malicious data. It operates at layer-
4 to layer-7. An IDP profile is a group of IDP signatures that have the same log and action settings. In
‘group view’ you can configure the same log and action settings for all IDP signatures by severity level in
the Add Profile screen. You may also configure signature exceptions in the same view.
38.2.3 Profile > Group View Screen
Select
Configuration > UTM Profile > IDP > Profile
and then click
Add
to create a new profile or select an
existing profile, then click a grouDosn the base profile box (or double-click the existing profile) to modify
it. Group view is displayed first by default.
Figure 503
Configuration > UTM Profile > IDP > Profile > Add > Edit: Group View
Summary of Contents for USG110
Page 27: ...27 PART I User s Guide ...
Page 195: ...195 PART II Technical Reference ...
Page 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Page 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Page 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Page 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...