TopGate命令行手册——IPS配置
engine show <cr> 命令描述:
显示 IPS 引擎设置参数。
engine tcpreset [on|off] 命令描述:
服务热线:8008105119
2
设置系统在丢弃报文时是否发送 tcpreset 命令。
IPS 配置
event
设置入侵防御的过滤规则。
event add tid <number> content <string1> dstport <string2> protocol <icmp|tcp|udp> srcport <string3> [msg <string4>]
命令描述:
添加自定义规则。
参数说明:
add tid number content
清空未被引用的自定义规则。
event show [tid <number1>] [type <system|custom>] [from <number2> to <number3>] 命令描述:
查看过滤规则。
参数说明:
show tid number1 type
system|custom
from number2 to
event showwhere tid <number>
命令描述:
查找某条规则属于哪个规则集。
参数说明:
show tid number1 使用说明:
查找某条规则属于哪个规则集 规则编号 数值,表示规则 ID 号,范围为 0-99999
该命令用于查找某条规则属于哪个规则集:查找规则编号 tid 为<number>的规则属
版权所有 不得翻印© 2011 天融信公司
商标声明
本手册中所谈及的产品名称仅做识别之用。手册中涉及的其他公 司的注册商标或是版权属各商标注册人所有,恕不逐一列明。
TOPSEC® 天融信公司
信息反馈
IPS 配置
目录
命令行详细说明 ......................................................................................................................................... 1 IPS ............................................................................................................................................................ 1 engine .................................................................................................................................................. 1 event .................................................................................................................................................... 3 eventset................................................................................................................................................ 5 fw-link.................................................................................................................................................. 8 policy................................................................................................................................................... 9 rules................................................................................................................................................... 11 service ............................................................................................................................................... 12 stat..................................................................................................................................................... 13 version ............................................................................................................................................... 13
已经添加的规则,会被攻击检测规则引用。
实例:
** 添加一个攻击检测自定义规则。
# event add tid 95000 content http.method;GET dstport 8000 protocol tcp srcport 8000 msg test
event modify [tid <number>] [content <string1>] [dstport <string2>] [protocol <icmp|tcp|udp>] [srcport <string3>] [msg <string4>] 命令描述:
按已经进入本命令模块书写。
下一级命令表
命令 engine event eventset fw-link policy rules service stat version
功能 ips 引擎配置 设置入侵防御设备的自定义规则 设置过滤规则的集合 防火墙联动配置 ips 策略配置 规则库升级配置 定义服务对象 ips 统计配置 ips 规则版本
修改自定义规则。
参数说明:
modify tid number content string1
修改自定义过滤规则 设置要修改的规则的 ID 号 数值,表示 ID 号 设置规则的内容 字符串,表示规则内容。规则内容具有特定的格式,
服务热线:8008105119
3
IPS 配置
dstport string2 protocol icmp|tcp|udp srcport string3 msg string4
查看过滤规则 规则编号 数值,表示规则 ID 号 设置要查看的规则的类型 system:系统预定义规则 custom:用户自定义规则 设置要查看的规则的起始 ID 号 数值,表示规则 ID 号 设置要查看的规则的结束 ID 号
服务热线:8008105119
4
IPS 配置
number3
数值,表示规则 ID 号。
设置检测模式 安全优先:当引擎处理压力过大时,不再检测,直接 丢弃数据包。 应用优先:当引擎处理压力过大时,不再检测,直接 转发数据包。 百分比数值,建议设置值为 50-80,用于调整 IPS 队 列缓冲的大小。
engine restart <cr> 命令描述:
重新启动 IPS 引擎。
engine save <cr> 命令描述:
设置检测模式 智能检测:根据协议和方向,智能选择检测的报文, 如 http 协议只检测数据包头,不检测数据文件及返回 的报文。 深度检测:不管协议和方向,每个报文都检测。
engine intellectiveinspect <number> 命令描述:
设置智能检测。 参数说明:
intellectiveinspect number
engine
设置 IPS 引擎的相关参数。
engine firewalllink [on|off] 命令描述:
防火墙联动开关。
engine inspect-mode [intellective|deeply] 命令描述:
设置检测S 配置
inspect-mode intellective deeply
IPS 配置 命令行手册
天融信 TOPSEC® 北京市海淀区上地东路 1 号华控大厦,100085 电话:(8610)82776666 传真:(8610)8277667 服务热线:800 810 5119 http: //
版权声明
本手册中的所有内容及格式的版权属于北京天融信公司(以下简 称天融信)所有,未经天融信许可,任何人不得仿制、拷贝、转译或 任意引用。
设置智能检测模式下,检测同一个连接中的前多少个 UDP 数据包。 数值,表示 UDP 包个数,默认检测前 16 个。
03-IPS 带宽管理典型配置-整本手册
IPS 带宽管理典型配置关键词:带宽管理摘要:本文主要介绍IPS系列产品带宽管理的典型配置。
缩略语:缩略语英文全名中文解释IPS Intrusion Prevention System 入侵防御系统目录1 特性简介 (3)2 应用场合 (3)3 注意事项 (3)4 配置举例 (3)4.1 组网需求 (3)4.2 配置思路 (4)4.3 配置步骤 (4)4.3.1 登录Web (4)4.3.2 创建安全区域 (5)4.3.3 新建段 (7)4.3.4 创建针对内网地址192.168.10.0/24迅雷限速、流媒体阻断的带宽管理策略 (8)4.3.5 创建针对内网其它IP地址迅雷阻断的带宽管理策略 (12)4.3.6 将配置激活 (14)4.3.7 将配置保存 (15)4.3.8 验证结果 (15)1 特性简介带宽管理模块是IPS设备的一个重要的基本模块,通过对网络流量的实时控制可以实现不同层次、不同粒度的带宽限制功能,IPS设备具有以下几种不同层次的带宽限制:(1) 限制分段总带宽段带宽,以物理组网为基础,进行带宽限制。
(2) 限制段上每个策略的总带宽策略带宽,以用户需求为基础,可以是基于IP地址的带宽限制。
(3) 限制每个policy的不同应用的带宽应用带宽,以各种应用为基础,对各种应用进行带宽限制。
按照上述的带宽分类我们可以结合策略、规则管理、服务管理,以及例外IP、列表IP、时间表等进行灵活的配置应用。
2 应用场合在运营商或企业用户的网络中,网络带宽资源非常宝贵,带宽管理功能对日趋严重的带宽滥用、误用进行控制,例如,对P2P、游戏等非法流量进行限速或阻断,使网络带宽资源被合理利用。
IPS设备的带宽管理功能应用于流量比较大的环境,如运营商、大中型企业和教育系统等网络,对这些网络中的非法流量进行限速或阻断。
3 注意事项T1000系列IPS适用于E1218及以上版本;T200-A/M/S产品适用于E1206及以上版本;IPS插卡适用于E2109P02及以上版本。
IPS入侵防御系统+操作手册(V1.05)
1.1.3 SSH 服务
设备支持 SSH 协议,当设备启动了 SSH 服务后,用户可以通过 SSH 方式登录到设备上,对设备 进行远程管理和维护。
表1-3 SSH 服务配置 操作
启动 SSHቤተ መጻሕፍቲ ባይዱ服务
命令 ssh service enable
说明 必选 缺省情况下,SSH 服务处于关闭状态
z 通过 SSH 方式登录设备使用的用户名和密码都是“sshadmin”。 z 通过 Telnet 和 SSH 方式同时登录设备的用户总数不能超过 7。
H3C IPS 入侵防御系统 操作手册
杭州华三通信技术有限公司
资料版本:20090624-C-1.05
声明
Copyright © 2008-2009 杭州华三通信技术有限公司及其许可者 版权所有,保留一切权利。
未经本公司书面许可,任何单位和个人不得擅自摘抄、复制本书内容的部分或全部,并不得以任何 形式传播。
1-2
目录
1 接口管理配置..................................................................................................................................... 1-1 1.1 简介 ................................................................................................................................................... 1-1 1.2 接口管理配置..................................................................................................................................... 1-1 1.2.1 以太网接口配置 ...................................................................................................................... 1-1 1.2.2 Combo接口配置...................................................................................................................... 1-2 1.2.3 接口显示和维护 ...................................................................................................................... 1-2
联想网御IPS快速开始指南
联想网御入侵防御系统IPS 快速配置指南声明:z本手册所含内容若有任何改动,恕不另行通知。
z在法律法规的最大允许范围内,联想网御科技(北京)有限公司除就本手册和产品应负的瑕疵担保责任外,无论明示或默示,不作其它任何担保,包括(但不限于)本手册中推荐使用产品的适用性和安全性、产品的适销性和适合某特定用途的担保。
z在法律法规的最大允许范围内,联想网御科技(北京)有限公司对于您的使用或不能使用本产品而发生的任何损坏(包括,但不限于直接或间接的个人损害、商业利润的损失、业务中断、商业信息的遗失或任何其它损失),不负任何赔偿责任。
z本手册含受版权保护的信息,未经联想网御科技(北京)有限公司书面允许不得对本手册的任何部分进行影印、复制或翻译。
联想网御科技(北京)有限公司中国北京海淀区中关村南大街6号中电信息大厦8层目录目录 (III)第1章登录系统 (1)第2章主要组网模式及举例 (4)2.1串联接入 (4)第3章入侵防护 (6)3.1基础配置 (6)3.2IPS检测 (7)3.3抗攻击 (10)3.3.1 保护策略 (10)3.3.2 全局抗攻击 (13)3.4IPS统计报表 (14)第1章登录系统IPS提供三种管理方式:1)WEB界面管理2)串口命令行管理3)远程SSH登录管理,其中管理方式1)和2)是默认开启的,3)默认是关闭的。
在串口命令行管理中,管理客户端的配置是38400-8-N-1,其中需要注意的是波特率配置为38400 bps,管理主机默认连接的CONSOLE。
Console口的必要配置如下图所示,图1-1端口通信参数设置联想网御IPS上电自检,系统自动进行配置,自检结束后提示用户键入回车,直到出现命令行提示符,此时输入:u空格c,出现密码提示符时输入密码leadsec,之后就可以进入用户需要的视图中进行配置。
举例进入配置试图Please press ENTER to enter system.IPS>u cPassword:IPS#configureIPS(config)#在WEB界面管理中,管理主机默认只能连接接口g0/0/0,如果需要连接其它网口,必须进行相应的设置。
Cisco IPS(5.x)配置操作详解
Cisco IPS(5.x)配置操作详解2010-02-10 23:38:10 来源: 【大中小】文章摘要:一、IPS Initual 1.使用管理员账号登陆IPS,默认下,用户名/密码:cisco/cisco;如果你是第一次登陆该IPS,那么IPS会提示你改变默认密码;2.使用setup命令,进入对话框配置--- System Configur-一、IPS Initual1.使用管理员账号登陆IPS,默认下,用户名/密码:cisco/cisco;如果你是第一次登陆该IPS,那么IPS会提示你改变默认密码;2.使用setup命令,进入对话框配置--- System Configuration Dialog ---At any point you may enter a question mark '?' for help.User ctrl-c to abort configuration dialog at any prompt.Default settings are in square brackets '[]'.Current Configuration:service hostnetwork-settingshost-ip 10.1.9.201/24,10.1.9.1host-name sensortelnet-option disabledftp-timeout 300login-banner-textexittime-zone-settingsoffset 0standard-time-zone-name UTCexitsummertime-option disabledntp-option disabledexitservice web-serverport 443exitCurrent time: Wed May 5 10:25:35 2004Continue with configuration dialog?[yes]:输入yes或直接回车,进入配置对话框;配置完成后使用show configuration验证配置;二、Setting UP the Sensor2.1 Configuring Network Settings使用Network面板来配置sensor的网络参数和通信参数;路径:Configuration > Sensor Setup > Networkl Hostname——设置sensor的名字;l IP Address——设置sensor的IP地址,默认地址是10.1.9.201;l Network Mask——默认掩码是255.255.255.0l Default Route——指定默认网关;默认是10.1.9.1l Ftp Timeout——当sensor和FTP Server通信的时候,指定FTP Client在超时之前等待时间,默认是300秒;l Web Server Settings——设置web server安全级别和接口参数—Enable TLS/SSL——在web server上启用TLS和SSL加密;默认下是启用的;—Web server port——Web Server使用的TCP接口号;默认为443;l Remote Access——启用sensor的远程接入—Enable Telnet——启用或禁用Sensor的Telnet管理,默认为禁用;图例:2.2 Configuring Allowed Hosts配置允许访问Sensor的主机地址或网段;路径:Configuration > Sensor Setup > Allowed Hosts;l IP Address——允许访问sensor的IP地址;l Network Mask——掩码决定是主机地址还是网段;图例:2.3 Configuring SSHSSH提供安全的接入和认证,SSH加密到sensor的连接,并提供对接入用户的认证,SSH 同时也提供sensor和其他设备联动时的认证和加密;SSH使用以下的任何一种方法认证主机:l Password;l 用户RSA public key;2.3.1 Defining Authorized Keys为客户端使用RSA认证方法登陆SSH server,定义client的public keys;在client上使用RSA key产生工具产生公钥/密钥,将公钥提交给SSH server;配置路径:Configuration > Sensor Setup > SSH > Authorized Keys(这个配置是用于client 通过ssh 登录ips.并且一旦配置完毕key就不需要密码了.认证的途径叫rsa authentication)图例:2.3.2 Defining Known Host Keys在该域下,定义当Sensor SSH到其他设备上的时候,其他设备的Pbulic Keys;把要登陆设备的IP地址填入之后,点Retrieve Host Key,Sensor将会自动将目标设备的Pbulic Key接收回来;配置路径:Configuration > Sensor Setup >SSH > Known Host Keys.2.3.3 Sensor KeyIPS Sensor自身SSH key,你可以使用Generate Key按钮重新产生一个新的Sensor SSH key;路径:Configuration > Sensor Setup > SSH > Sensor Key2.4 Configuring Certificates2.4.1 Trusted Hosts增加主block sensors或Sensor下载更新时的TLS和SSL服务器的证书,你可以通过写入IP 地址,然后Sensor会将目标的证书接收回来;路径:Configuration > Sensor Setup > Certificate > Trusted Hosts;2.4.2 Server Certificate服务器自身的证书;2.5 Configuring Users用户有以下角色:l Administrators——最高权限,可以察看并修改所有配置;l Operators——可以察看配置和事件,但是只能够修改以下选项:—Signature tuning (priority,disable or enable)—Virtual sensor definition—Managed routers—Their user passwordsl Viewers——可以察看所有配置和事件,但是不能够修改任何配置,除了他们的密码外;l Service——特殊账号,可以进入IPS内核程序;路径:Configuration > Sensor Setup > Users三、Configuring Interfaces我们可以将sensing接口运行在混杂模式,也可以将接口配置为inline pairs,但是首先要将接口UP;Sensing 接口没有IP地址,因此该接口对于攻击者来说是不可见的。
售后培训天融信入侵防御产品配置与维护V
扩展模块插槽 参考《TOPSEC扩展模块安装手册》
设备安装
上线流程
安装环境
• 部署位置 – 依据设备的使用目的选择相应的安装位置 – 根据安装位置环境对设备进行软硬件配置
• 接口类型 – 根据网络设备部署位置配置不同的接口模块
新夺回主网关的地位。优先级相同的两设备中不存在抢占, 并且只有优先级高设备抢占优先级低的设备的主身份 对端同步:从对端机同步配置到本机上 本地同步:从本地机同步配置到对端上
配置物理接口
配置HA接口时,一定要将“ha-static”勾选,不然配置同步时会将该接口的信 息覆盖
配置物理接口
其实VRID组就是用来选主备的,默认的情况下,所有的接口都是属于VRID 0 的,我们可以创建一个VRID组(组号在1 到 255 之间),组优先级高的会优 先成为主,同时设备上也只能创建一个VRID组,后创建的VRID组会将前面创 建的覆盖掉
准备工具
• PC一台 – 拥有COM连接口 – 具有超级终端等远程操作程序
• Console线缆 – 随机附赠
• 相应的网络线缆/接口卡/模块 • 系统升级补丁 • 升级签名库
Console登录
ID:superman PWD:talent
Console端操作
虽然Console端可以对设备进行完整配置,但是我们建议操作在WebUI下完成 。 在设备上线前,对设备管理配置可在console端完成: •管理接口配置
入侵防御策略配置
在规则集引用部分,和v3保持一致,依然采用单 选的方式,而动作的执行在规则集里进行单独配 置。
入侵防御策略配置--检测引擎参数设置
IPS配置
12.4版本安装与配置命令行配置方法:签名定义文件SDF:Signature Definition FileSDF定义了它包含的每个签名,当签名被IOS IPS装载以后,IPS立即开始扫描新的签名。
默认情况下,IOS里面是不包含任何签名的。
下面有三种类型的签名供IOS IPS使用:attack-drop.sdf 83个签名,少于128MB内存的路由器使用。
128MB.sdf 300个签名,128或更多的路由器使用。
256MB.sdf 500个签名,256或以上的路由器使用。
以上签名都可以用于12.4以后的所有思科接入路由器。
如果Flash被清空的话,sdf文件也会被清空。
注意:12.4T-9以后的IOS,不再使用128MB.sdf 而是使用.pkg的文件。
-------------IPS配置-----pkg-版本>>12.4T-9-------1、下载IOS IPS文件从思科网站下载需要的签名文件到本地电脑上)地址:/support/downloads/go/Model.x?mdfid=281442967&mdfLevel=Softw are%20Family&treeName=Security&modelName=Cisco%20IOS%20Intrusion%20Prevention% 20System%20Feature%20Software&treeMdfId=268438162下载的文件:IOS-Sxxx-CLI.pkg: Signature package 下载最新的签名realm-cisco.pub.key.txt: Public Crypto key 公钥文件2、创建IPS-Signature文件夹mkdir ips3、配置IPS加密KEY拷贝下载的TXT文档中的公钥配置如下:crypto key pubkey-chain rsanamed-key realm-cisco.pub signaturekey-string30820122 300D0609 2A864886 F70D0101 01050003 82010F00 3082010A 0282010100C19E93 A8AF124A D6CC7A24 5097A975 206BE3A2 06FBA13F 6F12CB5B 4E441F1617E630D5 C02AC252 912BE27F 37FDD9C8 11FC7AF7 DCDD81D9 43CDABC3 6007D128B199ABCB D34ED0F9 085FADC1 359C189E F30AF10A C0EFB624 7E0764BF 3E53053E5B2146A9 D7A5EDE3 0298AF03 DED7A5B8 9479039D 20F30663 9AC64B93 C0112A35FE3F0C87 89BCB7BB 994AE74C FA9E481D F65875D6 85EAF974 6D9CC8E3 F0B08B8550437722 FFBE85B9 5E4189FF CC189CB9 69C46F9C A84DFBA5 7A0AF99E AD768C36006CF498 079F88F8 A3B3FB1F 9FB7B3CB 5539E1D1 9693CCBB 551F78D2 892356AE2F56D826 8918EF3C 80CA4F4D 87BFCA3B BFF668E9 689782A5 CF31CB6E B4B094D3F3020301 0001Quitcopy running-configure startup-configure(切记)3、开启IOS IPS特性ip ips name iosips [acl]4、配置Signature存储位置[存在第一步建立的文件夹里面]ip ips config location ips5、配置警告信息通知ip ips notify log6、配置Signature策略,对于Signature,必须一开始关闭所有的Signature,然后按照下面的方法开启某些需要的Signature,否则路由器会因内存溢出而崩溃!ip ips signature-categorycategory allretired true开启某一项Signature检测比如:ios_ipscategory ios_ips basicretired falseexitconfirm change y!在接口上启用IPSinterface e0/0ip ips iosips in|outexit加载pkg Signature文件copy tftp://199.1.1.1/IOS-S310-CLI.pkg idconf 注意:这里一定要加关键字idconf7、开启某一项具体的特性(前提是已经开启了其相关的类category):ip ips signature-definitionsignature 6130 10 //6130中的编号为10的特征码statusenabled falseexitexitexit此处建议使用CCP或SDM软件进行配置,用以了解类别的从属关系。
TopGate安装手册
服务热线:8008105119
-i-
网络卫士安全网关系统安装手册
1 前言
本安装手册主要介绍网络卫士安全网关的安装和使用。通过阅读本文档,用户可以了 解如何正确地在网络中安装网络卫士安全网关,并进行简单配置。
本章内容主要包括: z 本文档的用途 z 阅读对象 z 本文档的组织结构 z 本文档的基本约定 z 相关文档 z 如何联系天融信技术支持
1.1 文档目的....................................................................................................................................... 1 1.2 读者对象....................................................................................................................................... 1 1.3 文档组织....................................................................................................................................... 1 1.4 约定............................................................................................................................................... 1 1.5 相关文档....................................................................................................................................... 2 1.6 技术服务体系............................................................................................................................... 2
迈普交换机常用命令手册-v1
迈普交换机常用命令手册-v1迈普常用命令手册V1.3目录1概述 (1)2配置命令 (2)2.1系统模式及切换 (2)2.2基础配置 (4)2.2.1配置主机名 (4)2.2.2配置账户 (5)2.2.3配置登陆 (5)2.2.4配置Vlan (5)2.3配置端口 (6)2.3.1双工速率........................................................................................................ 错误!未定义书签。
2.4配置T RACK (6)2.5配置MSTP (7)2.6配置VRRP (7)2.7配置T RUNK (7)2.8多接口LINK-AGGREGATION (8)2.9配置ACL (8)2.10配置路由 (9)2.10.1静态路由 (9)2.10.2配置RIP (9)2.10.3配置OSPF (10)2.11管理配置 (10)2.11.1配置AAA (10)2.11.2配置端口镜像 (11)2.11.3文件管理 (11)2.11.4Logging (12)2.11.5配置SNMP (12)2.11.6配置NTP (13)3迈普常用命令 (14)3.1查找MP命令 (14)3.2常用命令 (14)3.2.1查看信息........................................................................................................ 错误!未定义书签。
3.2.2删除配置........................................................................................................ 错误!未定义书签。
3.2.3查看配置文件 (14)3.2.4查看路由配置 (14)3.2.5查看路由表 (14)3.2.6查看VRRP状态 (15)3.2.7查看二层接口信息 (15)3.2.8查看bfd信息 (15)3.2.9查看设备信息 (15)3.2.10查看用户信息 (15)1概述本手册编写的目的是为了使分行管理员快速掌握迈普MP2900路由交换一体机的常用命令,为设备运维工作提供帮助和指导。
TP-IPS配置指导书
附录G:XX工业集团数据/网络安全项目TippingPoint 入侵防御产品配置指导书目录1、XX集团IPS设备登陆密码相关 (2)2、IPS初始化配置: (2)3、WEB方式管理 (11)4、IPS对于P2P流量的限制 (11)5、系统OS与数字疫苗DV升级简介 (16)6、IPS入侵产品的注册指南 (18)7、其它相关文档 (24)1、XX集团IPS设备登陆密码相关登陆IPS网管接口地址、用户名称、密码等登陆用户名称:xx登陆用户密码:xx网管接口地址:192.168.15.250 (主面板会显示)可以在管理界面里面增加用户、更改密码、更改网管地址等登陆TMC网站用户名称、密码等登陆用户名称:xx登陆用户密码:xx2、IPS初始化配置:2.1 打开电源开关,按POWER键开机:∙ ✧双电源设备,如果只使用一个电源,设备会发出告警声。
按电源旁边的红色按钮,可以消除告警声∙ ✧100E在打开电源开关后,可能并不能启动设备,这个时候需要长按面板上绿色的勾5秒。
2.2 使用配置线与PC相连:✧这里采用的波特率是115200;✧配置线两端都是DB9的母头。
2.3 启动过程。
∙✧在启动过程中不要随意敲键盘,如果无意输入任意键会使启动中断,需要输入@来继续启动。
TippingPoint OSBootrom Version: 14Creation date: Dec 6 2004, 14:02:01Press any key to stop auto-boot...76543210auto-booting...boot device : ata=0,0unit number : 0processor number : 0host name : NDSfile name : autoflags (f) : 0x0Attaching to ATA disk device... done.Boot Count: 144, v14, /boot/2.1.4.6324/vxWorks [798a09445a4926a2a6976837683ed4e1] Loading /boot/2.1.4.6324/vxWorks...10662264 + 966376 + 13404276Starting at 0x108000...Attaching interface lo0...doneAdding 27893 symbols for standalone.-> [RTC] CMOS Clock: 2006-09-21 12:44:30 [UTC]/boot/ - Volume is OK/opt/ - Volume is OK/usr/ - Volume is OK/log/ - Volume is OK_____ ____ _|_ _|_ _ __ _ __ _ _ __ __ _| _ \ ___ _ _ __ | |_| | | | '_ \| '_ \| | '_ \ / _` | |_) / _ \| | '_ \| __|| | | | |_) | |_) | | | | | (_| | __/ (_) | | | | | |_|_| |_| .__/| .__/|_|_| |_|\__, |_| \___/|_|_| |_|\__||_| |_| |___/ a division of 3ComTippingPoint - Austin, Texas, USA - TOS Version : 2.2.4.6519 Build Date: Jun 21 2006, 17:04:48Digital Vaccine : 2.2.0.6825 Serial: U1200CF-3053-4206Hardware Rev :Loading------------------快速输入mkey然后回车,设置用户名密码(忘记密码也可以如此处理)Autoflash FPGAs: FPGA is up to date for MZDMWelcome to the TippingPoint Technologies Initial Setup wizard.Press any key to begin the Initial Setup Wizard or use the LCD panel.按任意建You will be presented with some questions along with default valuesin brackets[]. Please update any empty fields or modify them to matchyour requirements. You may press the ENTER key to keep the currentdefault value. After each group of entries, you will have a chance toconfirm your settings, so don't worry if you make a mistake.There are three security levels for specifying user names and passwords:这里有三个安全级别,为了加强安全性,建议选择为2级Level 0: User names and passwords are unrestricted.Level 1: Names must be at least 6 characters long; passwords at least 8.Level 2: In addition to level 1 restrictions, passwords must contain:- at least 2 alpha characters- at least 1 numeric character- at least 1 non-alphanumeric character如果选择为2级,则密码至少包含大小写字母、数字、非数字的三种,并且不少于8个字符Please specify a security level to be used for initial super-user nameand password creation. As super-user, you can modify the security levellater on via Command Line Interface (CLI) or Local Security Manager (LSM).选择2Security level [2]: 2创建用户名和密码Please enter a user name that we will use to create your super-useraccount. Spaces are not allowed.Name: xxDo you wish to accept [XX] <Y,[N]>:yPlease enter your super-user account password:Verify password:Saving information ...DoneXX集团这里初始密码设置为xxYour super-user account has been created.You may continue initial configuration by logging into your device.After logging in, you will be asked for additional information.The login prompt should appear in approximately 90 seconds.........重启后,输入用户名登录:Login: XXPassword:Entering Setup wizard...配置初始化,配置管理口:The host management port is used to configure and monitor this device viaa network connection (e.g., a web browser).设置管理接口的IP地址等Enter Management IP Address [0.0.0.0]: 192.168.15.250Enter Network Mask [255.255.255.0]: 255.255.255.0Enter Host Name [myhostname]: xxEnter Host Location [room/rack]: xxHost IP: 192.168.15.250Network Mask: 255.255.255.0Host Name: xxHost Location: xxEnter [A]ccept, [C]hange, or [E]xit without saving [C]:The default gateway is a router that enables this device to communicate withother devices on the management network outside of the local subnet.Do you require a default gateway? <Y,[N]>:nTimekeeping options allow you to set the time zone, enable or disabledaylight saving time, and configure or disable SNTP.配置管理方式,默认只是启用HTTPSWould you like to modify timekeeping options? <Y,[N]>:nServer options allow you to enable or disable each of the following servers: SSH, Telnet, HTTPS, HTTP, and SNMP.Would you like to modify the server options? <Y,[N]>:yEnable the SSH server? [Yes]: nEnable the Telnet server? [Yes]: nEnable the HTTPS server ('No' disables SMS access)? [Yes]: yEnable the HTTP server? [Yes]: nEnable the SNMP agent ('No' disables SMS and NMS access)? [No]: nSSH: NoTelnet: NoHTTPS: YesHTTP: NoSNMP: No (SMS and NMS access disabled)Enter [A]ccept, [C]hange, or [E]xit without saving [C]: aBased on your configuration of the CLI and Web servers, you can configureor monitor this device via the management port or the serial port.If you wish to run this wizard again, use the 'setup' command.查看配置:xx# dis configurationinterface mgmtEthernetip 192.168.15.250mask 255.255.255.0exitinterface ethernet 3 1negotiateduplex fulllinespeed 1000no shutdownexitinterface ethernet 3 2 negotiateduplex fulllinespeed 1000no shutdownexitinterface ethernet 3 3 negotiateduplex fulllinespeed 1000no shutdownexitinterface ethernet 3 4 negotiate--More--duplex fulllinespeed 1000no shutdownexitinterface ethernet 3 5 negotiateduplex fulllinespeed 1000no shutdownexitinterface ethernet 3 6 negotiateduplex fulllinespeed 1000no shutdownexitinterface ethernet 3 7 negotiateduplex fulllinespeed 1000no shutdownexitinterface ethernet 3 8 negotiate--More--duplex fulllinespeed 1000no shutdownexitinterface vnam 3 1no ipmask 255.255.255.0 shutdownexitinterface vnam 3 2no ipmask 255.255.255.0 shutdownexitinterface vnam 3 3no ipmask 255.255.255.0 shutdownexitinterface vnam 3 4no ipmask 255.255.255.0 shutdownexit--More--interface vnam 3 5no ipmask 255.255.255.0 shutdownexitinterface vnam 3 6no ipmask 255.255.255.0 shutdownexitinterface vnam 3 7no ipmask 255.255.255.0 shutdownexitinterface vnam 3 8no ipmask 255.255.255.0shutdownexitinterface settings poll-interval 2000 interface settings detect-mdi enable host name "xx"host location "xx"--More--host ip-filter permit any icmphost ip-filter permit any ipdefault-gateway 0.0.0.0sntp primary 192.43.244.18sntp secondary 192.5.41.40sntp duration 60sntp offset 1sntp port 123sntp timeout 1sntp retries 3no sntpuser options max-attempts 5user options expire-period 90user options expire-action expire user options lockout-period 5user options attempt-action lockout user options security-level 2 segment 3 1 name "Segment 1"segment 3 1 high-availability permit segment 3 1 link-down hubsegment 3 2 name "Segment 2"segment 3 2 high-availability permit segment 3 2 link-down hubsegment 3 3 name "Segment 3"--More--segment 3 3 high-availability permit segment 3 3 link-down hubsegment 3 4 name "Segment 4"segment 3 4 high-availability permit segment 3 4 link-down hubhigh-availability no iphigh-availability disableclock timezone GMTclock dstlog audit select generallog audit select loginlog audit select logoutlog audit select userlog audit select timelog audit select policylog audit select updatelog audit select bootlog audit select reportlog audit select hostlog audit select configurationlog audit select oamlog audit select smslog audit select cvalog audit select server--More--log audit select segmentlog audit select high-availabilitylog audit select monitorlog audit select ip-filterlog audit select conn-tablelog audit select host-communicationlog audit select tsecategory-settings attack-protection enable -action-set "Recommended" category-settings reconnaissance enable -action-set "Recommended" category-settings security-policy enable -action-set "Recommended" category-settings informational enable -action-set "Recommended" category-settings network-equipment enable -action-set "Recommended" category-settings traffic-normal enable -action-set "Recommended" category-settings misuse-abuse enable -action-set "Recommended" notify-contact "SMS" 1notify-contact "Remote System Log" 1notify-contact "Management Console" 1notify-contact "LSM" 1default-alert-sink period 1discovery age 0server no sshserver no telnetserver no httpserver https--More--server browser-checkmonitor threshold memory -major 90 -critical 95monitor threshold disk -major 90 -critical 95monitor threshold temperature -major 73 -critical 75no service-accesstse adaptive-filter mode automatictse afc-severity warningtse asymmetric-network enabletse connection-table timeout 1800tse logging-mode conditional -threshold 1.0 -period 600email-rate-limit 10lcd-keypad enablelcd-keypad backlight 50lcd-keypad contrast 16no nmsramdisk sync-interval block -1ramdisk sync-interval alert -1ramdisk sync-interval peer -1sms no v2sms no v3sms no must-be-ipno smssession timeout 20 -persist此时可以通过web方式https://192.168.15.250进行管理。
NGFW管理手册——IPS配置
IPS配置天融信TOPSEC® 北京市海淀区上地东路1号华控大厦 100085电话:+8610-82776666传真:+8610-82776677服务热线:+8610-8008105119版权声明 本手册中的所有内容及格式的版权属于北京天融信公司(以下简称天融信)所有,未经天融信许可,任何人不得仿制、拷贝、转译或任意引用。
版权所有不得翻印© 1995-2008 天融信公司商标声明 本手册中所谈及的产品名称仅做识别之用。
手册中涉及的其他公司的注册商标或是版权属各商标注册人所有,恕不逐一列明。
TOPSEC® 天融信公司信息反馈目录1入侵防御 (1)1.1IPS策略 (1)1.2IPS引擎 (7)1.3服务 (8)1.4动作 (9)1.5规则 (10)1.5.1系统规则 (10)1.5.2系统规则集 (11)1.5.3自定义规则 (14)1.5.4自定义规则集 (15)1.6规则库管理 (17)1.6.1系统规则库 (17)1.6.2自定义规则库 (18)1.7防火墙联动 (19)1.8IPS报表 (22)1.8.1攻击排名 (22)1.8.2详细事件 (22)2自定义规则使用说明 (24)A.1负载检测类规则选项 (24)A.2非负载检查类规则选项 (27)A.3IP (32)A.4TCP (34)A.5HTTP (35)A.6DNS (39)A.7FTP (42)A.8POP3 (44)A.9SMTP (45)A.10QQ (46)A.11MSN (47)A.12IMAP (48)1入侵防御天融信入侵防御设备是基于模式匹配和异常检测技术对网络数据进行在线数据解析和攻击检测的网络安全解决方案。
它通过对数据包进行规则匹配,对异常的数据包进行主动防御,从而保护网络的安全。
同时,天融信入侵防御设备可以实现与天融信防火墙的联动,对用户内部网络提供了全面、高效的安全保护。
本章内容主要包括:z IPS策略:介绍如何设置入侵防御规则。
