ZyXEL Communications ZyWALL 110 User Manual page 144

Hide thumbs Also See for ZyWALL 110:
Table of Contents

Advertisement

The following table describes the labels in this screen.
Table 63 Monitor > UTM Statistics > IDP
LABEL
Collect Statistics
Apply
Reset
Refresh
Flush Data
Total Session Scanned
Total Packet Dropped
Total Packet Reset
Top Entries By
#
Signature Name
Signature ID
Type
Severity
Source IP
Destination IP
Occurrences
The statistics display as follows when you display the top entries by source.
Chapter 6 Monitor
DESCRIPTION
Select this check box to have the ZyWALL/USG collect IDP statistics.
The collection starting time displays after you click Apply. All of the statistics in this
screen are for the time period starting at the time displayed here. The format is
year, month, day and hour, minute, second. All of the statistics are erased if you
restart the ZyWALL/USG or click Flush Data. Collecting starts over and a new
collection start time displays.
Click Apply to save your changes back to the ZyWALL/USG.
Click Reset to return the screen to its last-saved settings.
Click this button to update the report display.
Click this button to discard all of the screen's statistics and update the report display.
This field displays the number of sessions that the ZyWALL/USG has checked for
intrusion characteristics.
The ZyWALL/USG can detect and drop malicious packets from network traffic. This
field displays the number of packets that the ZyWALL/USG has dropped.
The ZyWALL/USG can detect and drop malicious packets from network traffic. This
field displays the number of packets that the ZyWALL/USG has reset.
Use this field to have the following (read-only) table display the top IDP log entries
by Signature Name, Source or Destination. This table displays the most
common, recent IDP logs. See the log screen for less common IDP logs or use a
syslog server to record all IDP logs.
Select Signature Name to list the most common signatures that the ZyWALL/USG
has detected.
Select Source to list the source IP addresses from which the ZyWALL/USG has
detected the most intrusion attempts.
Select Destination to list the most common destination IP addresses for intrusion
attempts that the ZyWALL/USG has detected.
This field displays the entry's rank in the list of the top entries.
This column displays when you display the entries by Signature Name. The
signature name identifies the type of intrusion pattern. Click the hyperlink for more
detailed information on the intrusion.
This column displays when you display the entries by Signature Name. The
signature ID is a unique value given to each intrusion detected.
This column displays when you display the entries by Signature Name. It shows
the categories of intrusions.
This column displays when you display the entries by Signature Name. It shows
the level of threat that the intrusions may pose.
This column displays when you display the entries by Source. It shows the source IP
address of the intrusion attempts.
This column displays when you display the entries by Destination. It shows the
destination IP address at which intrusion attempts were targeted.
This field displays how many times the ZyWALL/USG has detected the event
described in the entry.
ZyWALL/USG Series User's Guide
144

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents