Table 32: Deep Inspection Profile Actions - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Copyright © 2010, Juniper Networks, Inc.
Categories are as follows:
Server Protection Pack—Designed to protect servers.
Client Protection Pack—Designed to protect remote and home offices.
Worm Mitigation Pack—Designed to protect against worms.
Base (Default) Pack—All signatures. Might be too large for some devices.
DI Attack Objects and Groups—Add a profile member to the profile object. Each profile
member can contain attack object groups, and you can add multiple profile members
to the profile object. Within each profile member:
Select the attack object groups you want to include in this profile member.
Configure the action you want the security device to take when an attack object
within the profile member matches traffic. Table 32 on page 335 lists DI profile actions.

Table 32: Deep Inspection Profile Actions

Action
Description
none
The security device takes no action against the connection.
ignore
The security device ignores the remainder of a connection after an attack object
is matched.
drop
The security device drops a matching packet before it can reach its destination
packet
but does not close the connection. Use this action to drop packets for attacks in
traffic that is prone to spoofing, such as UDP traffic. Dropping a connection for
such traffic could result in a denial of service that prevents you from receiving traffic
from a legitimate source IP address.
For TCP connections, dropping a single packet will result in the same packet being
resent. So, Drop Packet settings are translated to Drop Connection settings for
TCP connections.
drop
The security device drops the connection without sending a RST packet to the
connection
sender, preventing the traffic from reaching its destination. Use this action to drop
connections for traffic that is not prone to spoofing.
close client
The security device closes the connection and sends a RST packet to both the
and server
client and the server.
close client
The security device closes the connection to the client but not to the server.
close server
The security device closes the connection to the server but not to the client.
Chapter 8: Configuring Objects
335

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents