Ifindexin Group; Asn Source Group; Asn Destination Group; Qos Group - Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

ASN Source Group

ASN Destination
Group

IFIndexIn Group

IFIndexIn Group

QoS Group

Table B-6 Custom Views - PolicyViolations (continued)
Group
Objects
Remote_Access_
Remote_Access_Shell - Detects bidirectional flows, where
Policy_Violation
remote hosts were connecting to local remote access servers.
Detection of any of the following access technologies include:
Citrix, PCAnywhere, SSH, Telnet, or VNC.
P2P_
This group includes:
Policy_Violation
Application_
This group includes:
Policy_Violation
• Unknown_Local_Service - Detects an active service on a local host.
Compliance_
Clear_Text_Application_Usage - Detects flows where the
Policy_Violations
application types use clear text passwords. Applications that
usage for this view include Telnet, FTP, and POP. We
recommend that you tune this view to add or remove additional
applications.
STRM detects the ASN values from network flows. When STRM detects a ASN
source values in a flow, STRM creates a new object in the ASN Source group. For
example, if STRM detects an ASN 238 flow within the source traffic, the object
ASN238 is created in the ASNSource group.
STRM detects the ASN values from network flows. When STRM detects a ASN
destination values in a flow, STRM creates a new object in the ASN destination
group. For example, if STRM detects an ASN 238 flow within the destination traffic,
the object ASN238 is created in the ASNDestination group.
STRM detects the IFIndex values from network flows. When STRM detects
IFIndex values in a flow, STRM creates a new object in the respective group.
STRM detects the IFIndex values from network flows. When STRM detects
IFIndex values in a flow, STRM creates a new object in the respective group.
Default QoS groups include:
Table B-7 Custom Views - QoS View
QoS Group
Network Control
Object
STRM Administration Guide
Local_P2P__Server - Detects flows indicating a P2P server is
operating on the local network. This can be in violation of local
network policy.
Local_P2P_Client - Detects flows indicating a P2P client is operating
on the local network. This can be in violation of local network policy.
NNTP_to_Internet - Detects flows indicating an NNTP news client is
operating on the local network. This may be in violation of local
network policy.
Group Objects
Specifies QoS values related to link layer and routing
protocols.
Default Custom Views
335

Advertisement

Table of Contents
loading

Table of Contents