
Chapter 22 IDP Commands
Note: You CANNOT change the base profile later!
Table 103 Editing/Creating Anomaly Profiles
COMMAND | DESCRIPTION |
idp anomaly newpro [base {all none}] | Creates a new IDP anomaly profile called newpro. |
| newpro uses the base profile you specify. Enters sub- |
| command mode. All the following commands relate to |
| the new profile. Use exit to quit |
Sets | |
no | Clears |
| is medium. |
|
|
Sets for how many seconds the ZyWALL blocks all | |
| packets from being sent to the victim (destination) of a |
| detected anomaly attack. |
|
|
[no] | Activates TCP scan detection options where |
[alert] block} | |
| |
| |
| portscan |
| detection logs or alerts and blocking. no deactivates |
| TCP scan detection, its logs, alerts or blocking. |
[no] | Activates or deactivates UDP scan detection options |
[alert] block} | where |
| portscan |
| |
| |
| portsweep}. Also sets UDP |
| and blocking. no deactivates UDP scan detection, its |
| logs, alerts or blocking. |
[no] | Activates or deactivates IP scan detection options where |
[alert] block} | |
| |
| |
| |
| |
| alerts and blocking. no deactivates IP scan detection, |
| its logs, alerts or blocking. |
[no] | Activates or deactivates ICMP scan detection options. |
sweep} {activate log [alert] block} | Also sets ICMP |
| blocking. no deactivates ICMP scan detection, its logs, |
| alerts or blocking. |
[no] | Activates or deactivates open port scan detection |
[alert] block} | options. Also sets open port |
| alerts and blocking. no deactivates open port scan |
| detection, its logs, alerts or blocking. |
Sets for how many seconds the ZyWALL blocks all | |
| packets from being sent to the victim (destination) of a |
| detected anomaly attack. |
|
|
[no] | Activates or deactivates TCP, UDP, IP or ICMP flood |
flood | detection. Also sets flood detection logs or alerts and |
block} | blocking. no deactivates flood detection, its logs, alerts |
| or blocking. |
| 185 |
ZyWALL (ZLD) CLI Reference Guide | |
|
|