Setting Vlan Tags For Idp Rules; Setting Severity For Idp Rules - Juniper NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide

Setting VLAN Tags for IDP Rules

Setting Severity for IDP Rules

480
NOTE: Packet captures are restricted to 256 packets before and after the
attack.
You can choose to apply rules to traffic on certain VLANs only. Normally, for a rule to
take effect, it must match the packet source, destination, service, and attack objects. If
the VLAN cell is populated with a value other than any, then the rule will also consider
the packet's VLAN tag when determining a match.
The IDP, Exempt, Backdoor, SYN Protector, Traffic Anomalies, and Network Honeypot
rulebases support VLAN matching. VLAN matching is only supported in Transparent and
Sniffer modes.
NOTE: VLAN matching is supported in IDP 4.1 and later. Rules with a VLAN
Tag field set to anything other than any are removed from the rulebase before
NSM sends the security policy to an IDP device that does not support VLAN
tags.
VLAN tag matching can be set to any, none, a particular VLAN tag value, or a range of
VLAN tag values. Use VLAN objects to create individual VLAN tags or ranges of VLAN
tags. You can assign more than one VLAN object to a rule. To assign a VLAN object to a
rule, or to set the VLAN Tag value to none, right-click in the VLAN Tag cell of the rule.
VLAN matching works as follows:
Any: Matches traffic with any or no VLAN tag (default)
Single tag: Matches traffic with that specific tag only
Range of tags: Matches traffic with any tag in that range
None: Matches only traffic that has no VLAN tag
(This column only appears when you view the security policy in Expanded Mode. To
change the security policy view from Compact Mode to Expanded Mode, from the menu
bar, select View > Expanded Mode.)
You can override the inherent attack severity on a per-rule basis within the IDP rulebase.
You can set the severity to either Default, Info, Warning, Minor, Major, or Critical.
To change the severity for a rule, right-click the Severity column of the rule and select a
severity.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.4

Table of Contents