ZyXEL Communications USG40 User Manual page 498

Usg series
Hide thumbs Also See for USG40:
Table of Contents

Advertisement

Table 199 Configuration > UTM Profile > SSL Inspection > Profile > Add / Edit (continued)
LABEL
DESCRIPTION
Add
Click this to configure settings to a signature that are different to the severity level to which
it belongs.
Remove
Select an existing signature exception and then click this to delete the exception.
Activate
To turn on an entry, select it and click Activate.
Inactivate
To turn off an entry, select it and click Inactivate.
Log
To edit an item's log option, select it and use the Log icon. These are the log options:
no: Select this option on an individual signature or a complete service group to have the
ZyWALL/USG create no log when a packet matches a signature(s).
log: Select this option on an individual signature or a complete service group to have the
ZyWALL/USG create a log when a packet matches a signature(s).
log alert: An alert is an e-mailed log for more serious events that may need more
immediate attention. Select this option to have the ZyWALL/USG send an alert when a
packet matches a signature(s).
Action
To edit what action the ZyWALL/USG takes when a packet matches a signature, select the
signature and use the Action icon.
none: Select this action on an individual signature or a complete service group to have the
ZyWALL/USG take no action when a packet matches the signature(s).
drop: Select this action on an individual signature or a complete service group to have the
ZyWALL/USG silently drop a packet that matches the signature(s). Neither sender nor
receiver are notified.
reject-sender: Select this action on an individual signature or a complete service group to
have the ZyWALL/USG send a reset to the sender when a packet matches the signature. If
it is a TCP attack packet, the ZyWALL/USG will send a packet with a 'RST' flag. If it is an
ICMP or UDP attack packet, the ZyWALL/USG will send an ICMP unreachable packet.
reject-receiver: Select this action on an individual signature or a complete service group
to have the ZyWALL/USG send a reset to the receiver when a packet matches the
signature. If it is a TCP attack packet, the ZyWALL/USG will send a packet with an a 'RST'
flag. If it is an ICMP or UDP attack packet, the ZyWALL/USG will do nothing.
reject-both: Select this action on an individual signature or a complete service group to
have the ZyWALL/USG send a reset to both the sender and receiver when a packet matches
the signature. If it is a TCP attack packet, the ZyWALL/USG will send a packet with a 'RST'
flag to the receiver and sender. If it is an ICMP or UDP attack packet, the ZyWALL/USG will
send an ICMP unreachable packet.
#
This is the entry's index number in the list.
Status
The activate (light bulb) icon is lit when the entry is active and dimmed when the entry is
inactive.
SID
Type the exact signature ID (identification) number that uniquely identifies a ZyWALL/USG
IDP signature.
Log
These are the log options. To edit this, select an item and use the Log icon.
Action
This is the action the ZyWALL/USG should take when a packet matches a signature here. To
edit this, select an item and use the Action icon.
OK
Click OK to save your settings to the ZyWALL/USG, and return to the profile summary
page.
Cancel
Click Cancel to return to the profile summary page without saving any changes.
Chapter 30 SSL Inspection
ZyWALL/USG Series User's Guide
498

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Usg40wUsg210Usg310Usg1100Usg60Usg1900 ... Show all

Table of Contents