12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring Intrusion PreventionConfiguring Intrusion PreventionAfter you use the Activate Intrusion Prevention wizard to activate IPS and create a basic configuration,you can further refine the configuration.1 From Policy Manager, select Tasks > Intrusion Prevention > Configure.The Intrusion Prevention dialog box appears, which lists the policies that have already been created.2 Select the policy you want to configure and click Configure.The General Intrusion Prevention Settings page for that policy appears.About intrusion severity levelsThe proxy settings for intrusion prevention generally use three separate security levels. These threeintrusion severity levels look for the following:HighVulnerabilities that allow remote access or execution of code, such as buffer overflows, remotecommand execution, password disclosure, backdoors, and security bypass.MediumVulnerabilities that allow access, disclose server-side source code to attackers, and deny accessto legitimate users. Examples are directory traversal, file/source disclosure, DoS, SQL injection,and cross-site scripting.LowVulnerabilities that do not allow the attacker to directly get access, but allow the attacker to getinformation that can be used in an attack. For example, an attacker can send a command thatgets information about the operating system, IP addresses, or topology of a network.Signatures that get access to software applications with vulnerabilities (such as signatures thatdo not have very specific content) also get this level of severity.Some signatures that would usually be in the High or Medium level are put in lower levels if their contentis not very detailed. They are also put in lower levels if they have a wide scope that could cause falsepositives.316 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!