Manuals
/
Force10 Networks
/
Computer Equipment
/
Network Card
Force10 Networks
100-00055-01 manual Writing Rules
Models:
100-00055-01
1
74
132
132
Download
132 pages
61.04 Kb
71
72
73
74
75
76
77
78
<
>
Specifications
Install
Locating P-Series Serial Numbers Requesting a Hardware Replacement
Configuration
Wireshark
pnic resetconf on page pnic restart on page
Command Line Interface
Compiler Errors
Information Symbols
Accessing iSupport Services
Page 74
Image 74
74
Writing Rules
Page 73
Page 75
Page 74
Image 74
Page 73
Page 75
Contents
May 27
P-Series Installation and Operation Guide
Version
Statement of Conditions
Copyright 2008 Force10 Networks
Trademarks
USA Federal Communications Commission FCC Statement
Installation
Contents
Contents
Preface
Chapter
Command Line Interface
Graphical User Interface
Web-based Management
Compiling Rules
Command Line Reference
Basic Unix Commands
Writing Rules
Appendix F
Appendix E
Glossary
Technical Support
Objectives
Preface
About this Guide
Audience
Additional Resources
Information Symbols
Related Documents
P-Series Release Notes
Installation
Chapter
PB-10GE-2P
System Specifications
Physical Connections
Step Task
Security Check
Booting
Configuration
Upgrading Software
cd upgradedirectory
mkdir ~/upgradedirectory
filename ~/upgradedirectory
scp username@serverabsolutepath
cd upgradedirectory/firmware
Command
cd upgradedirectory/pnic-compiler
gmake install
Chapter
Returning to the Default Configuration
Getting Started
To begin inspecting and filtering traffic you must
Getting Started
Chapter
Introduction
Hardware Architecture Overview
Types of Rules
Sample Rules and Firmware
Firewall Deployment” on page
Rule Management
Deploying the P-Series
10-Gigabit
Inline Deployment
Fail-safe Deployment
Optical Bypass 10-Gigabit
P1P0
Highly-available Deployment
Passive Deployment
10-Gigabit
Network Tap 10-Gigabit 10-Gigabit
Capturing Matched Traffic
Network Switch with SPAN port
P-Series P10
Capturing to a Host CPU
M1 P1 P0 M0
Mirroring to Another Device
PB-10GE-2P
Traffic to Monitor
Chapter 4 Graphical User Interface
GUI Commands
Command Description
Managing Rules, Policies, and Firmware
PNIC0 Not Active
GUI” on page
Editing Dynamic Rules with the GUI
directory see “Editing Dynamic Rules with the GUI” on page
To manage firmware, see “Selecting Firmware with the GUI” on page
To change capture/forward policies
Managing Capture/Forward Policies with the GUI
To modify dynamic rules
fn9000014
Selecting Firmware with the GUI
fn9000013
Runtime Statistics
Figure 19 Runtime Statistics for Channel 0 and 1-FPGA Loaded
Graphical User Interface
Reloading Firmware
Graphical User Interface
To launch the P-Series Node Manager
Chapter 5 Web-based Management
Launching the P-Series Node Manager
Figure 21 Lauching the P-Series Node Manager
Web-based Management
Monitoring System Performance on page
Managing the P-Series using Node Manager
Web-browser Security Certificates
Managing Firmware Images on page
Monitoring System Performance
Managing Firmware Images
Managing the Network Interface Card
Figure 25 P-Series Node Manager Card Management Panel
Web-based Management
Managing Policies
Figure 26 P-Series Node Manager Policy Managment Panel
Web-based Management
Sguil Server
Chapter 6 Network Security Monitoring
P-Series Sensors
Sguil Client
Installing the Sguil Server
Installing the Sguil System
Installing the Sguil Sensor
Hardware and Software Requirements
Wireshark
Installing the Sguil Client
Uninstalling the Sguil Server
Installation Files
# win32 example set TLSPATH c/progra~1/Tcl/lib/tls1.4.1/tls14.dll
Writing New Rules
Running the Sguil System
Running the Sguil Sensor
Running the Sguil Server
Running the Sguil Client
To run the Sguil Client
fn90028mp
fn90027mp
CLI commands are given in Command Line Reference on page
Chapter 7 Command Line Interface
CLI Commands
Editing Dynamic Rules with the CLI
In Figure
To enable MAC rewriting
Removing VLAN Tags
Command Line Interface
Rules Capacity
Compiling Rules
Creating Rules Files
Compiling Rules
page
Target Device
Match non-IP Traffic
3 Match Fragmented IPv4 Packets or IPv4 Packets w/ Options
Maximum String
Segmentation Evasion Rules
see Figure 36 on page
see Figure 37 on page
Enter command gmake from pnic-compiler directory
P-Series Installation and Operation Guide, version
Figure 36 pnic-Compiler Option
Summary of configuration
Starting and Stopping the pnic-Compiler
to which the .mapping files in /usr/local/pnic
Configuration and Generated Files
which the .bit files in /usr/local/pnic/0 are
Compiler Errors
Firmware Filenames
Snort Rule Headers
Writing Rules
Snort Rule Syntax
Action
Protocol
Source Addresses
Ports
Direction Operator
Snort Rule Options
P-Series Rule Syntax
P-Series Supported Snort Keywords
Destination Address and Port
Dynamic
Keyword
Static
protocol
Writing Stateful Rules
Stateful Matching
= si ⎬
Equation
∧ si
then cpi
Stateful Rule Examples
In Table
The meta.rules File
Support for Snorts flow Keyword
Handling Segmentation Evasion
Support for Snorts within Keyword
Anomalous TCP Flags
Writing Rules
Chapter
Firewall
Deploying the P-Series as a Firewall
Verify Drop mode is Enabled
Enabling the Firewall
Drop mode Disabled Drop mode Enabled
Figure 39 Enabling and Disabling Drop Mode
Allowing Traffic through the Firewall
Writing Rules for a Firewall Deployment
#permit let through and do not log to the host
pnic aggregate-mode-enable on page pnic apply-firmware on page
Appendix A Command Line Reference
pnic aggregate-mode-disable on page
pnic default-drop-disable on page pnic default-drop-enable on page
pnic updatemacvalue on page pnic vlan-remove-disable on page
pnic aggregate-mode-disable
pnic temp-mem-disable on page pnic temp-mem-enable on page
pnic vlan-remove-enable on page pnic web-gui-start on page
pnic aggregate-mode-enable
pnic apply-firmware
pnic show-firmwares
Parameters Command History Example
Commands
Display the available firmware
Enable the capturing of packets via direct memory access
pnic capture-off
pnic capture-on
Syntax Parameters Command History Example
Syntax Parameters Command History Example
pnic cardstatus
Commands
Commands
pnic default-drop-disable
pnic compilerules
pnic diag
pnic default-drop-enable
Temporary memory is disabled while the firewall is enabled
Parameters Command History Example
Version PMAIN2.3.0.014 root@localhost SW#
Parameters Command History Example
Usage Information
pnic flow-teardown-disable
pnic flow-teardown-disable
pnic flow-teardown-enable
pnic flow-teardown-enable
pnic getmachashindex
value for an IP address pairs
Disable MAC rewriting
pnic gui
Enable MAC rewriting
pnic updatemacvalue
Example
pnic gui Command Example
P-Series Installation and Operation Guide, version
pnic help
pnic help
Syntax Command History Example
output omitted
Syntax Parameters Command History Example
pnic linkdown
pnic linkup
Commands
Commands
pnic loadconf
Parameters Command History Example
Syntax Parameters Command History
Address
Corresponding Parameter
pnic loadeproms number
pnic loadeproms
pnic loadparams deprecated
pnic loadparams number
Address
Corresponding Parameter
Syntax Parameters
pnic loadrules
Command History Example Usage Information
pnic macrewrite-off
pnic macrewrite-on
pnic off deprecated
Syntax pnic off
Syntax Parameters Command History Example
pnic on deprecated
Usage Information Related Commands
pnic on deprecated
pnic passive-mode-disable
pnic params
Command
pnic passive-mode-enable
pnic passive-mode-enable
Commands
Syntax Parameters Command History Example
pnic resetconf
pnic restart
Stop capturing and matching
Enable the network interface
pnic sguil-sensor-start
Disable the network interface
Syntax Command History Example
Commands
Stop the Sguil sensor using the command pnic sguil-sensor-stop
Syntax Parameters Command History Example
pnic sguil-sensor-start -f
Commands
pnic sguil-sensor-stop
Syntax Parameters Command History Example
pnic sguil-sensor-start Start the Sguil sensor
Syntax Parameters Command History Example
pnic showconf
pnic show-firmwares
Commands
Commands
pnic showtech
Command History Example
Syntax Parameters Command History
Enable the network interface
pnic start
Load the capture/block configuration Load the runtime parameters
Disable the network interface using the command pnic stop
Commands
pnic stop
Enable the network interface
Syntax Parameters Command History Example
pnic temp-mem-disable
pnic temp-mem-enable
pnic temp-mem-disable
pnic updatemacvalue
Use this command with the MAC rewrite feature
Enable MAC rewriting
pnic vlan-remove-disable
pnic vlan-remove-disable
pnic vlan-remove-enable
pnic vlan-remove-enable
Disable the web server using the command pnic web-gui-stop
pnic version
pnic web-gui-start
Display the driver version
Commands
Enable the web server using the command pnic web-gui-start
pnic web-gui-stop
Command
Example
Commands
pnic web-gui-start
Related
Appendix A
ack number
Appendix B
Snort Keywords
dsize number number
Keyword
Description
uricontent ! “datastring”
Keyword
Rule Syntax
Appendix B
Evasion Rules
Appendix C Meta and Evasion Rules
meta Rules
Appendix C
Command
Appendix D Basic Unix Commands
Unix Commands
Description
Description
vi Commands
Command
? text
Appendix E
Glossary
State
Snort
SPAN Port
Static Rules
Technical Support
Accessing iSupport Services
Appendix F
Manual Pages
Serial Number see Locating P-Series Serial Numbers on page
Contacting the Technical Assistance Center
Locating P-Series Serial Numbers
Requesting a Hardware Replacement
To request replacement hardware, follow these steps
Technical Support