SonicWALL TZ 180 manual SonicWALL Deep Packet Inspection, DPI Overview, How Does DPI Work?

Page 16

SonicWALL Deep Packet Inspection

SonicWALL Deep Packet Inspection

This section provides an overview to the SonicWALL Intrusion Prevention Service (DPI). This section contains the following subsections:

DPI Overview

How Does DPI Work?

Benefits

DPI Overview

Deep Packet Inspection (DPI) looks at the data portion of the packet. The Deep Packet Inspection technology includes intrusion detection and intrusion prevention. Intrusion detection finds anomalies in the traffic and alerts the administrator. Intrusion prevention finds the anomalies in the traffic and reacts to it, preventing the traffic from passing through.

How Does DPI Work?

Deep Packet Inspection is a technology that allows a SonicWALL Security Appliance to classify passing traffic based on rules. These rules include information about layer 3 and layer 4 content of the packet as well as the information that describes the contents of the packet’s payload, including the application data (for example, an FTP session, an HTTP Web browser session, or even a middleware database connection). This technology allows the administrator to detect and log intrusions that pass through the SonicWALL Security Appliance, as well as prevent them (i.e. dropping the packet or resetting the TCP connection). SonicWALL’s Deep Packet Inspection technology also correctly handles TCP fragmented byte stream inspection as if no TCP fragmentation has occurred.

Benefits

Deep Packet Inspection technology enables the firewall to investigate farther into the protocol to examine information at the application layer and defend against attacks targeting application vulnerabilities. This is the technology behind SonicWALL Intrusion Prevention Service. SonicWALL’s Deep Packet Inspection technology enables dynamic signature updates pushed from the SonicWALL Distributed Enforcement Architecture.

16 SonicWALL TZ 180 TotalSecure

Image 16
Contents Introduction What is TotalSecure?Document Scope Every SonicWALL TotalSecure solution includes the following Benefits of TotalSecureSonicWALL Gateway Anti-Virus GAV OverviewHow Does GAV Work? BenefitsSonicWALL Gateway Anti-Virus/Intrusion Prevention Features SonicWALL GAV Multi-Layered Approach Remote Site Protection Internal Network ProtectionHttp File Downloads SonicWALL GAV Architecture Server ProtectionDisabling the SonicWALL GAV/IPS Engine Protocol HandlingSmtp IPS Overview SonicWALL Intrusion Prevention ServiceHow Does IPS Work? What is a Zone? SonicWALL Anti-Spyware SonicWALL Anti-Spyware Security ServiceSpyware Threat SonicWALL Anti-Spyware CFS Overview SonicWALL Content Filtering Service PremiumHow Does CFS Premium Work? DPI Overview SonicWALL Deep Packet InspectionHow Does DPI Work? Deep Packet Inspection Flow Diagram SonicWALL Security Dashboard Security Dashboard Overview SonicWALL Security Dashboard What is Security Dashboard? How Does the Security Dashboard Work?Registering Your Appliance on MySonicWALL Registering Your Appliance on MySonicWALL TotalSecure Configuration Task List Registering Your SonicWALL Security ApplianceEnabling SonicWALL GAV Setting Up SonicWALL GAV ProtectionApplying SonicWALL GAV Protection on Interfaces Applying SonicWALL GAV Protection on Zones SonicOS Enhanced Edit ZoneViewing SonicWALL GAV Status Information Specifying Protocol Filtering Updating SonicWALL GAV SignaturesEnabling Inbound Inspection Configuring Client Alerts and an Exclusion List Enabling Outbound Smtp InspectionConfiguring a SonicWALL GAV Exclusion List Configuring Client AlertsRestricting File Transfers Viewing SonicWALL GAV Signatures Displaying SignaturesNavigating the Gateway Anti-Virus Signatures Table Enabling SonicWALL IPSEnable IPS Logging Brute-force Baseline SetupSetting Up SonicWALL Anti-Spyware Protection Enabling SonicWALL Anti-Spyware Glossary Setting Up CFS PremiumSpecifying Spyware Danger Level Protection Glossary Related Documentation Solution Document Version History Version Number Date Related Documentation SonicWALL TZ 180 TotalSecure
Related manuals
Manual 34 pages 40.02 Kb Manual 38 pages 55.88 Kb