An Intrusion Prevention System (IPS) is a threat detection method to detect and prevent identified threats. IPS continuously monitors the network to identify the possible malicious incidents and captures information about the identified incidents. The IPS takes preventative action to prevent future attacks.
In this section, you can create Intrusion Prevention Action Profile to be used along with the Intrusion Prevention profiles created on OBJECT | Profile Objects > Intrusion Prevention > Intrusion Prevention Profiles page.
To configure a custom Intrusion Prevention Action Profile
Do one of the following:
Add a new Security Action Profile.
Edit an existing Security Action Profile.
Hover over an existing Security Action Profile and click the Edit icon.
Click the Intrusion Prevention tab.
Select the Threat Profile to be used to build an action profile.
Global Settings |
To apply the rules defined by SonicOS. Go to step 7 if you select Global Settings. |
Profile Settings |
To customize the rules for a specific requirement. Skip step 7 if you select Profile Settings. |
Select the profile to be applied to Prevent and Log from the respective drop-down menus. These options are not available if you set the Intrusion Prevention Profile as Global Settings.
Prevent | To restrict the transfer of files with specific attributes. Enabling Prevent restricts data file transfers for each protocol, except the TCP Stream. |
Log | To keep a record of your SonicWallIntrusion Prevention traffic. |
You can select the default or custom Profiles created on OBJECT | Profile Objects > Intrusion Prevention > Intrusion Prevention Profiles page. For more information, refer to Adding Intrusion Prevention Profiles.
Select the Low, Medium, and High Priority/Risk options based on your needs to Prevent, Log, and for how long to use the Redundancy Filters.
Low, Medium, and High Priority/Risk options are not available if you select Profile Settings because your Intrusion Prevention Profile addresses those capabilities.