Intrusion Detection - CyberGuard SG300 User Manual

Cyberguard sg series
Table of Contents

Advertisement

Note
Implementations of protocols such as H.323 can vary, so if you are experiencing
problems then you can try disabling the module.
Check Enable Connection Logging to log connections to the system log as they are
established and expire, however this may result in a lot of log messages if you have a
large or busy network.

Intrusion Detection

Note
The SG300, SG530, SG550, SG560, SG570 and SG630 provide Basic Instrusion
Detection and Blocking only.
The CyberGuard SG appliance provides two intrusion detection systems (IDS): the
lightweight and simple-to-configure Basic Intrusion Detection and Blocking, and the
industrial strength Advanced Intrusion Detection and Prevention.
These two systems take quite different approaches. Basic Intrusion Detection offers a
number of dummy services to the outside world, which are monitored for connection
attempts. Clients attempting to connect to these dummy services can be blocked.
Advanced Intrusion Detection uses complex rulesets to detect known methods used by
intruders to circumvent network security measures, which it either blocks, or logs to a
remote database for analysis.
150
Firewall

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SG300 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Sg530Sg550Sg565Sg570Sg575Sg580 ... Show all

Table of Contents