Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 109

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

Enter values for the parameters:
Step 5
Table 5-9 Flow Processor Parameters
Parameter
Create Flow Bundles
Maximum Number of
Flows
Time Difference for
Duplicate Flows
Type A Superflows
Type B Superflows
Description
Specify one of the following options:
Yes - Allows the Flow Processor to group flows that have
similar properties.
No - Disables the bundling of flows
Specify the maximum number of flows you wish to send from
the Flow Processor to the Classification Engines. If set to 0,
the number of flows is unlimited.
Specify the time difference threshold that determines if
duplicate flows are present, in microseconds. The default is
500000.
Specify the threshold for type A superflows, which is one
host sending data to many hosts. A unidirectional flow that is
an aggregate of all flows that have the same protocol,
source bytes, source hosts, destination network, destination
port (TCP and UDP flows only), TCP flags (TCP flows only),
ICMP type, and code (ICMP flows only) but different
destination hosts.
Specify the threshold for type B superflows, which is many
hosts sending data to one host. A unidirectional flow that is
an aggregate of all flows that have the same protocol,
source bytes, source packets, destination host, source
network, destination port (TCP and UDP flows only), TCP
flags (TCP flows only), ICMP type, and code (ICMP flows
only), but different source hosts.
STRM Administration Guide
Configuring STRM Components 101

Advertisement

Table of Contents
loading

Table of Contents