12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Setting Blocked Sitesconfigure the Firebox to protect against DDoS attacks. Use the arrow keys to set the maximum allowednumber of connections that your servers and clients can receive each second.Setting Blocked SitesThe Blocked Sites feature helps prevent network traffic from systems you know or think are dangerousor a security risk. After you find the source of suspicious traffic, you can block all the connections withthat IP address. You can also configure the Firebox to send a log message each time the source tries toconnect to your network. From the log file, you can see the services that they use to attack.A blocked site is an IP address that cannot make a connection through the Firebox. If a packet comesfrom a system that is blocked, it does not get through the Firebox®.There are two different types of blocked IP addresses:• Permanently blocked sites — on a list in the configuration file that you set manually. This isknown as the Blocked Sites list.• Auto-blocked sites — IP addresses that the Firebox adds or removes on a temporary blocked sitelist. The Firebox uses the packet handling rules that are specified for each service. For example,you configure the Firebox to block the IP addresses that try to connect to a blocked port. Theseaddresses are then blocked for a specified time. This is known as the Temporary Blocked Sites list.You can use a list of temporarily blocked sites with log messages to help you make a decision aboutwhich IP addresses to block permanently.Blocking a site permanentlyYou use Policy Manager to permanently block a host that you know is a security risk. For example, a universitycomputer that hackers use frequently is a good host to block.1 From Policy Manager, select Setup > Intrusion Prevention > Blocked Sites.The Blocked Sites Configuration dialog box appears.2 Click Add.The Add Site dialog box appears.138 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!