D-Link DFL-1660 User Manual page 284

Network security firewall
Hide thumbs Also See for DFL-1660:
Table of Contents

Advertisement

6.5.8. SMTP Log Receiver for IDP
Events
Specify the Action:
An action is now defined, specifying what signatures the IDP should use when scanning data matching the rule,
and what NetDefendOS should do when a possible intrusion is detected. In this example, intrusion attempts will
cause the connection to be dropped, so Action is set to Protect. The Signatures option is set to
IPS_MAIL_SMTP in order to use signatures that describe attacks from the external network that are based on the
SMTP protocol.
1.
Select the Rule Action tab for the IDP rule
2.
Now enter:
Action: Protect
Signatures: IPS_MAIL_SMTP
Click OK
If logging of intrusion attempts is desired, this can be configured by clicking in the Rule Actions tab when
creating an IDP rule and enabling logging. The Severity should be set to All in order to match all SMTP attacks.
In summary, the following will occur: If traffic from the external network to the mail server occurs, IDP will be
activated. If traffic matches any of the signatures in the IPS_MAIL_SMTP signature group, the connection will be
dropped, thus protecting the mail server.
284
Chapter 6. Security Mechanisms

Advertisement

Table of Contents
loading

Table of Contents