•
DXS-3326GSR (Version R4.30-B11 or later)
•
DXS-3350SR (Version R4.30-B11 or later)
•
DHS-3618 (Version R1.00-B03 or later)
•
DHS-3626 (Version R1.00-B03 or later)
Tip: Switch firmware versions should be the latest
It is advisable when using ZoneDefense to make sure that all switches have the latest
firmware version installed.
Using Threshold Rules
A threshold rule will trigger ZoneDefense to block out a specific host or a network if the
connection limit specified in the threshold rule is exceeded. The triggering limit can be one of
two types:
•
Connection Rate Limit
This can be triggered if the rate of new connections per second to the firewall exceeds a
specified threshold.
•
Total Connections Limit
This can be triggered if the total number of connections to the firewall exceeds a specified
threshold.
Threshold rules have parameters which are similar to those for IP Rules. These parameters specify
what type of traffic a threshold rule applies to.
A single threshold rule object has the following properties:
•
Source interface and source network
•
Destination interface and destination network
•
Service
•
Type of threshold: Host and/or network based
Traffic that matches the above criteria and causes the host/network threshold to be exceeded
will trigger the ZoneDefense feature. This will prevent the host/networks from accessing the
switch(es). All blocking in response to threshold violations will be based on the IP address of the
host or network on the switch(es). When a network-based threshold has been exceeded, the
source network will be blocked out instead of just the offending host.
For a detailed discussion of how to specify threshold rules, see Section 10.3, "Threshold Rules".
Manual Blocking and Exclude Lists
As a complement to threshold rules, it is also possible to manually define hosts and networks
that are to be statically blocked or excluded. Manually blocked hosts and networks can be
blocked by default or based on a schedule. It is also possible to specify which protocols and
845
Chapter 12: ZoneDefense