Detect Intrusions - Polycom realpresence group series Administrator's Manual

Hide thumbs Also See for realpresence group series:
Table of Contents

Advertisement

To allow users to customize the workspace, select the Allow Access to User Settings option to make the
User Settings choice on the Settings screen available to users on the local interface's Home screen.
If the Polycom RealPresence Group system is paired with a Polycom Touch Control, selecting Allow
Access to User Settings makes the RealPresence Group Series system tab available on the Touch
Control User Settings screen.
User Settings contains the following options, most of which are also available to administrators under Admin
Settings. These settings are not available in the Maximum Security Profile unless otherwise noted.
● Meeting Password (available in the Maximum Security Profile)
● Backlight Compensation (available in the Maximum Security Profile)
● Mute Auto-Answer Calls
● Allow Other Participants in a Call to Control Your Camera
● Auto Answer Point-to-Point Video
● Auto Answer Multipoint Video
● Allow Video Display on Web

Detect Intrusions

The Polycom RealPresence Group system logs an entry to the security log when it detects a possible
network intrusion. This logging is controlled by the setting Admin Settings > Security > Global Security
> Access > Enable Network Intrusion Detection System (NIDS). The security log prefix identifies the
type of packet detected, as shown in the following table.
Prefix
SECURITY: NIDS/unknown_tcp
SECURITY: NIDS/unknown_udp
SECURITY: NIDS/invalid_tcp
SECURITY: NIDS/invalid_icmp
SECURITY: NIDS/unknown
SECURITY: NIDS/flood
Following the message prefix, the security log entry includes the timestamp and the IP, TCP, UDP, ICMP, or
ICMPv6 headers. For example, the following security log entry shows an "unknown_udp" intrusion:
2009-05-08 21:32:52 WARNING kernel: SECURITY: NIDS/unknown_udp IN=eth0
OUT= MAC=00:e0:db:08:9a:ff:00:19:aa:da:11:c3:08:00 SRC=172.18.1.80
DST=172.18.1.170 LEN=28 TOS=0x00 PREC=0x00 TTL=63 ID=22458 PROTO=UDP
SPT=1450 DPT=7788 LEN=8
Polycom, Inc.
Packet Type
Packet that attempts to connect or probe a closed TCP port
Packet that probes a closed UDP port
TCP packet in an invalid state
ICMP or ICMPv6 packet in an invalid state
Packet with an unknown protocol number in the IP header
Stream of ICMP or ICMPv6 ping requests or TCP connections to an opened
TCP port
Security
136

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents