Chapter 3 IPS Filtering
The default security profile is set to the ANY ==> ANY security zone pair with all IPS filters configured with the default Digital Vaccine settings. With the default profile in place, all incoming and outgoing traffic in any security zone configured on the device is monitored according to the recommended IPS filter configuration. You can edit the default Security Profile to customize the security zones that it applies to and create custom filter settings, or create your own Security Profiles as required.
Note Before creating Security Profiles, verify that the Network and System configuration on the X family device is set up correctly for your environment. In particular, you need to configure all required Security Zones before you can create the Security Profiles to protect them. For details, see “System” on page 217 and “Network” on page 129.
You can monitor and configure IPS from the IPS menu pages available in the LSM. For additional information, see the following topics:
•“Security Profiles” on page 17
•“IPS Digital Vaccine (DV) Filters” on page 23
•“Traffic Threshold Filters” on page 38
Using the IPS
You can monitor and configure the settings for IPS from the IPS menu pages available in the LSM. The following menu options are available:
•Security Profiles
•Traffic Threshold
•Action Sets — View, manage and create actions that define the operations a filter performs when a traffic match occurs.
•IPS Services
•Preferences
For details on each menu option, see the following topics:
•“Security Profiles” on page 17
16 X Family LSM User’s Guide V 2.5.1