SonicOS 7.0 Security Services Administration Guide
- SonicOS 7.0
- Summary
- Managing the SonicWall Gateway Anti-Virus Service
- SonicWall GAV Multi-Layered Approach
- SonicWall GAV Architecture
- Activating the Gateway Anti-Virus, Anti-Spyware, and Intrusion Prevention License
- Setting Up SonicWall Gateway Anti-Virus Protection
- Viewing SonicWall Gateway Anti-Virus Signatures
- Anti-Spyware Service
- Intrusion Prevention Service
- Configuring Geo-IP Filters
- Configuring Botnet Filters
- Configuring App Control
- About App Control Policy Creation
- Viewing App Control Status
- Configuring App Control Global Settings
- Configuring App Control Signatures
- Configuring App Control Signatures by Category
- Configuring App Control Signatures by Application
- Configuring App Control Advanced by Signature
- Viewing Signatures
- Viewing by All Categories and All Applications by Applications
- Viewing by All Categories and All Applications by Signatures
- Viewing by All Categories and All Applications by Category
- Viewing Just One Category
- Viewing Just One Application
- Displaying Details of Signature Applications
- Displaying Details of Application Signatures
- Configuring Content Filter
- SonicWall Support
IPS Global Settings
-
Enable IPS - Click this setting to enable the Intrusion Prevention. After service is enabled, the next three checkboxes become available.
Select the checkboxes of the interface ports to monitor, WAN, LAN, or DMZ/WLAN/OPT. These three checkboxes become available when Enable IPS is checked.
- The next section allows you to configure the level of attack to monitor and in what way. You can set different levels of protection for High Priority Attacks, Medium Priority Attacks, and Low Priority Attacks.
- Prevent All - Select this option to detect, log, and prevent all attacks of this level.
- Detect All - Select this option to detect and log only.
- Log Redundancy Filter (Seconds) - To prevent the log from becoming overloaded with entries for the same attack, enter a value in the field. For example, if you entered a value of 30 seconds and there were 100 SubSeven attacks during that period of time, only one attack would be logged during that 30 second period.
- Configure IPS Settings - This is one of four buttons below the attack level chart. It brings up the following dialog box.
- IPS Exclusion List
- Enable IPS Exclusion List - Select this field to configure the SonicWall security appliance to skip Intrusion Prevention enforcement for a specified IP address object or range of address objects. The fields that follow are only available when this field is selected.
- Use Address Object — Select an address object from the drop-down menu.
- Use Address Range —Fill in the address range limits to exclude. If the address range is selected, you can Add or Delete All of the choices.
- Update IPS Signature Database - Select to force the firmware to download all signatures.
- Reset IPS Settings & Policies - Click to reset your IPS settings to the defaults.
- Import CSV File - This button imports the CSV file.
- Click OK or Cancel when you are done with this page.
Save - brings up a dialog box requesting more information about the schedule and persistence of the individual changes you have made.
Cancel - clears all the settings on the screen.
Was This Article Helpful?
Help us to improve our support portal