Procedure To Create A New Profile; Creating New Profiles; Profiles: Traffic Anomaly - ZyXEL Communications ZYWALL 1050 - V2.00 EDITION 1 User Manual

Internet security gateway
Table of Contents

Advertisement

Chapter 30 ADP
Table 142 Anti-X > ADP > Profile (continued)
LABEL
Base Profile
(Icons)

30.7 Creating New Profiles

You may want to create a new profile if not all rules in a base profile are applicable to your
network. In this case you should disable non-applicable rules so as to improve ZyWALL ADP
processing efficiency.
You may also find that certain rules are triggering too many false positives or false negatives.
A false positive is when valid traffic is flagged as an attack. A false negative is when invalid
traffic is wrongly allowed to pass through the ZyWALL. As each network is different, false
positives and false negatives are common on initial ADP deployment.
You could create a new 'monitor profile' that creates logs but all actions are disabled. Observe
the logs over time and try to eliminate the causes of the false alarms. When you're satisfied
that they have been reduced to an acceptable level, you could then create an 'inline profile'
whereby you configure appropriate actions to be taken when a packet matches a rule.

30.7.1 Procedure To Create a New Profile

To create a new profile:
1 Click the 'add' icon in the Anti-X > ADP > Profile screen to display a pop-up screen
allowing you to choose a base profile.
2 Select a base profile (see
details screen.
3 Type a new profile name
4 Enable or disable individual rules
5 Edit the default log options and actions.

30.8 Profiles: Traffic Anomaly

The traffic anomaly screen is the second screen in an ADP profile. Traffic anomaly detection
looks for abnormal behavior such as scan or flooding attempts. Select Anti-X > ADP >
Profile > Traffic Anomaly. If you made changes to other screens belonging to this profile,
make sure you have clicked OK or Save to save the changes before selecting the Traffic
Anomaly tab.
446
DESCRIPTION
This is the base profile from which the profile was created.
Click the Add icon in the column header to create a new profile. A pop-up screen
displays requiring you to choose a base profile from which to create the new profile.
Click an Edit icon to edit an existing profile.
Click a Remove icon to delete an existing profile.
Table 141 on page
445) and then click OK to go to the profile
ZyWALL 1050 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 1050

Table of Contents