Chapter 30 Idp; Overview; What You Can Do In This Chapter; What You Need To Know - ZyXEL Communications ZyWall 110 User Manual

Security firewalls
Hide thumbs Also See for ZyWall 110:
Table of Contents

Advertisement

30.1 Overview

This chapter introduces packet inspection IDP (Intrusion, Detection and Prevention), IDP profiles,
binding an IDP profile to a traffic flow, custom signatures and updating signatures. An IDP system
can detect malicious or suspicious packets and respond instantaneously. IDP on the ZyWALL/USG
protects against network-based intrusions.

30.1.1 What You Can Do in this Chapter

• Use the UTM Profile > IDP > Profile screen
and signature information. Click the Add or Edit icon in this screen to bind an IDP profile to a
traffic direction.
• Use the UTM Profile > IDP > Profile > Add screen
profile, edit an existing profile or delete an existing profile.
• Use the UTM Profile > IDP > Custom Signature screens
a new custom signature, edit an existing signature, delete existing signatures or save signatures
to your computer.

30.1.2 What You Need To Know

Packet Inspection Signatures
A signature identifies a malicious or suspicious packet and specifies an action to be taken. You can
change the action in the profile screens. Packet inspection signatures examine OSI (Open System
Interconnection) layer-4 to layer-7 packet contents for malicious data. Generally, packet inspection
signatures are created for known attacks while anomaly detection looks for abnormal behavior.
Applying Your IDP Configuration
Changes to the ZyWALL/USG's IDP settings affect new sessions (not the sessions that already
existed before you applied the changed settings).

30.1.3 Before You Begin

• Register for a trial IDP subscription in the Registration screen. This gives you access to free
signature updates. This is important as new signatures are created as new attacks evolve. When
the trial subscription expires, purchase and enter a license key using the same screens to
continue the subscription.
C
HAPTER
(Section 30.2 on page
ZyWALL/USG Series User's Guide
484
485) to view registration
(Section 30.2.2 on page
487) to add a new
(Section 30.3 on page
3 0
IDP
496) to create

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents