Specify the rule the router uses when applying
this service.
|
- Click Rule next to Ids.
- Click Add new entry next to
Rule.
- In the Name box, enter the
identifier for the collection of terms that constitute this rule.
- In the Comment box, enter
the comment.
- From the Match Direction list,
select the direction in which the rule match is applied.
- input—To apply the rule match
on input.
- output—To apply the rule match
on output.
- input-output—To apply the rule
match bidirectionally.
- Expand rule.
- Click Term next to rule.
- Click Add new entry next to Term.
- In the Name box, enter the
Identifier for the term.
- In the Comment box, enter
the comment.
|
Specify input conditions for the IDS term.
|
- Expand term.
- Click From next to term.
- In the Comment box, enter
the comment.
- Expand From.
- From the listed match conditions, select the ones
that are applicable for Ids.
The match conditions listed are Application Sets, Applications,
Destination Address, Destination Address Range, Destination Prefix
List, Source Address, Source Address Range, and Source Prefix List.
|
Define the IDS term actions.
|
- Click Then next to term.
- In the Comment box, enter
the comment.
- Expand Then.
|
Specify the type of data to be aggregated.
|
- Click Aggregation next
to Then.
- In the Comment box, enter
the comment.
- From the Source Prefix list,
select the prefix value for source IPv4 address aggregation.
Range: 1 through 32
- From the Destination Prefix list, select the prefix value for destination IPv4 address aggregation.
Range: 1 through 32
- From the Source Prefix Ipv6 list, select the prefix value for source IPv6 address aggregation.
Range: 1 through 128.
- From the Destination Prefix Ipv6 list, select the prefix value for destination IPv6 address aggregation.
Range: 1 through 128
|
Specify handling of entries in the IDS events
cache.
|
- Click Force Entry next
to Then.
- Select one of the following:
- force-entry—To ensure that
the entry has a permanent place in the IDS cache after one event is
registered.
- ignore-entry—To ensure that
all IDS events are ignored.
|
Set logging values for this IDS term.
|
- Click Logging next to
Then.
- In the Comment box, enter
the comment.
- From the Threshold list, select
the logging threshold number of events per second.
- Select the Syslog check box
to enable system logging.
|
Configuring session limit.
|
- Click Session Limit next
to Then.
- In the Comment box, enter
the comment.
- Expand Session Limit.
- Click By Destination , By Source or By Pair next to
Session Limit.
- In the Comment box, enter
the comment.
- In the Maximum box, enter
the maximum number of open sessions per IP address or subnet per application.
Range: 1 through 32,767
- In the Rate box, enter the
maximum number of sessions per second per IP address or subnet per
application.
Range: 4 through 32,767
- In the Packets box, enter
the maximum peak packets per second per application or IP address.
Range: 4 through 2147483647
- From the Hold Time list, select
the length of time for which to stop all new flows once the rate of
events exceeds the threshold set by one or more of the maximum, packets,
or rate statements.
Range: 0 through 60
|
Enable SYN-cookie defenses against SYN attacks.
|
- Click Syn Cookie next
to Then.
- In the Comment box, enter
the comment.
- From the Threshold list, select
the SYN-cookie defense number of SYN attacks per second.
- From the Mss list, select
the maximum segment size value used in TCP delayed binding.
Default: 1500
Range: 128 through 8192
|
Specify the rule set the router uses when
applying this service.
|
- Click Rule Set next to
Ids.
- Click Add new entry next to
Rule Set.
- In the Name box, enter the
rule the router uses when applying this service.
- In the Comment box, enter
the comment.
- Expand rule-set.
- Click Rule next to rule-set.
- Click Add new entry next to
Rule.
- In the Name box, enter the
rule the router uses when applying this service.
- In the Comment box, enter
the comment.
|