Example: Enabling The Malicious Url Blocking Option (Nsm Procedure); Interface Types In Screenos Devices Overview - Juniper NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 Manual

Configuring screenos devices guide
Hide thumbs Also See for NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01:
Table of Contents

Advertisement

Configuring ScreenOS Devices Guide

Example: Enabling the Malicious URL Blocking Option (NSM Procedure)

Related
Documentation

Interface Types in ScreenOS Devices Overview

50
In this example, you define three malicious URL strings and enable the malicious URL
blocking option. Then, enable fragment reassembly for the detection of the URLs in
fragmented HTTP traffic arriving at an Untrust zone interface.
Add a NetScreen-5GT security device. Choose Model when adding the device and
1.
configure the device as running ScreenOS 5.x.
In the device navigation tree, select Network > Zone. Double-click the Untrust zone.
2.
The General Properties screen appears.
Select TCP/IP Reassembly for ALG.
3.
In the Zone navigation tree, select Mal-URL. Configure three malicious URL strings:
4.
a. Click the Add icon to display the new Malicious URL ID dialog box. Configure the
following and click OK:
For Malicious URL ID, enter Perl.
For HTTP Header Pattern, enter scripts/perl.exe.
For Minimum Length Before CRLF, enter 14.
b. Click the Add icon to display the new Malicious URL ID dialog box. Configure the
following options, and then click OK:
For Malicious URL ID, enter CMF.
For HTTP Header Pattern, enter cgi-bin/phf.
For Minimum Length Before CRLF, enter 11.
c. Click the Add icon to display the new Malicious URL ID dialog box. Configure the
following options, and then click OK:
For Malicious URL ID, enter DLL.
For HTTP Header Pattern, enter 210.1.1.5/msadcs.dll.
For Minimum Length Before CRLF, enter 18.
Click OK to save your changes to the zone, and then click OK again to save the
device configuration.
Predefined Screen Options Overview on page 40
Malicious URL Protection on page 49
The Interface screen displays the physical interfaces available on the security device.
Some security devices support functional zone interfaces, which are either a separate
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents