Chapter 3 IPS Filtering

Settings table, change the global State or Action for a filter Category Group if required. For more detailed instructions, see “Edit Category Settings for a Filter Group” on page 30.

STEP 5 Click Create.

After you create the Security Profile, you can edit the Security Profile and perform additional advanced configuration to create filter overrides and specify global limits and exceptions.

Edit a Security Profile

STEP 1

STEP 2

STEP 3

On the LSM menu, select IPS > Security Profiles.

On the Create Security Profiles page, click the (edit) icon to edit the desired security pro- file.

In the Security Zones section, modify the security zone pair configuration, if necessary.

STEP A Select the Incoming and Outgoing Security Zone.

STEP B

STEP C

Click Add to table.

Repeat this process until you have added all the required security zone pairs.

Click to delete a security zone.

STEP 4 Review or configure advanced configuration options. If the advanced options are not visible, click Show Advanced Options. Do any of the following as needed:

In the Profile Details (Advanced) section in the Category Settings table, change the global State or Action for a filter Category Group if required. For more detailed instructions, see “Edit Category Settings for a Filter Group” on page 30.

To review filters or add a filter to the Security Profile for customization, locate the filter using the Search Filters button or View all filters link. For details, see “Edit Individual Filter Settings” on page 32.

Configure global IP address limits or exceptions if required. For details, see “Configure Global IP address Limits and Exceptions” on page 34.

STEP 5 Click Save to update the Security Profile.

For additional information, see the following topics:

“View DV Filters” on page 26

“Edit DV Filter Category Settings” on page 29

“Port Scan/Host Sweep Filters” on page 35

22 X Family LSM User’s Guide V 2.5.1