ZyXEL Communications ZyWALL USG 200 Series User Manual page 620

Unified security gateway
Hide thumbs Also See for ZyWALL USG 200 Series:
Table of Contents

Advertisement

Chapter 34 IDP
Table 168 Configuration > Anti-X > IDP > Custom Signatures > Add/Edit (continued)
LABEL
Flow
Flags
Sequence
Number
Ack Number
Window Size
Transport
Protocol: UDP
Port
Transport
Protocol: ICMP
Type
Code
ID
Sequence
Number
Payload Options
620
DESCRIPTION
If selected, the signature only applies to certain directions of the
traffic flow and only to clients or servers. Select Flow and then select
the identifying options.
Established: The signature only checks for established TCP
connections
Stateless: The signature is triggered regardless of the state of the
stream processor (this is useful for packets that are designed to
cause devices to crash)
To Client: The signature only checks for server responses from A to
B.
To Server: The signature only checks for client requests from B to A.
From Client:.The signature only checks for client requests from B to
A.
From Servers: The signature only checks for server responses from
A to B.
No Stream: The signature does not check rebuilt stream packets.
Only Stream: The signature only checks rebuilt stream packets.
Select what TCP flag bits the signature should check.
Use this field to check for a specific TCP sequence number.
Use this field to check for a specific TCP acknowledgement number.
Use this field to check for a specific TCP window size.
Select the check box and then enter the source and destination UDP
port numbers that will trigger this signature.
Use this field to check for a specific ICMP type value.
Use this field to check for a specific ICMP code value.
Use this field to check for a specific ICMP ID value. This is useful for
covert channel programs that use static ICMP fields when they
communicate.
Use this field to check for a specific ICMP sequence number. This is
useful for covert channel programs that use static ICMP fields when
they communicate.
The longer a payload option is, the more exact the match, the faster
the signature processing. Therefore, if possible, it is recommended to
have at least one payload option in your signature.
ZyWALL USG 100/200 Series User's Guide

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 100 series

Table of Contents