Application Patrol Profile - ZyXEL Communications ZyWALL 1100 User Manual

Zywall/usg series
Hide thumbs Also See for ZyWALL 1100:
Table of Contents

Advertisement

Classification of Applications
There are two ways the ZyWALL/USG can identify the application. The first is called auto. The
ZyWALL/USG looks at the IP payload (OSI level-7 inspection) and attempts to match it with known
patterns for specific applications. Usually, this occurs at the beginning of a connection, when the
payload is more consistent across connections, and the ZyWALL/USG examines several packets to
make sure the match is correct. Before confirnation, packets are forwarded by App Patrol with no
action taken. The number of packets inspected before confirmation varies by signature.
Note: The ZyWALL/USG allows the first eight packets to go through the security policy,
regardless of the application patrol policy for the application. The ZyWALL/USG
examines these first eight packets to identify the application.
The second approach is called service ports. The ZyWALL/USG uses only OSI level-4 information,
such as ports, to identify what application is using the connection. This approach is available in case
the ZyWALL/USG identifies a lot of "false positives" for a particular application.
Custom Ports for SIP and the SIP ALG
Configuring application patrol to use custom port numbers for SIP traffic also configures the SIP
ALG to use the same port numbers for SIP traffic. Likewise, configuring the SIP ALG to use custom
port numbers for SIP traffic also configures application patrol to use the same port numbers for SIP
traffic.
Finding Out More
• You must configure services in Objects > Application.
• See Configuration > BWM chapter for detailed information on bandwidth management.

26.2 Application Patrol Profile

Use the application patrol Profile screens to customize action and log settings for a group of
application patrol signatures. You then link a profile to a policy.Use this screen to create an
application patrol profile, and view signature information. It also lists the registration status and
details about the signature set the ZyWALL/USG is using.
Note: You must register for the IDP/AppPatrol signature service (at least the trial) before
you can use it.
A profile is an application object(s) or application group(s) that has customized action and log
settings.
Click Configuration > UTM Profile > App Patrol > Profile to open the following screen.
Chapter 26 Application Patrol
ZyWALL/USG Series User's Guide
428

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents