Index

and address objects 513 and schedules 513 prerequisites 123

fragmentation flag 437 fragmentation offset 437

FTP 605

additional signaling port 270 and address groups 606 and address objects 606 and certificates 605

and zones 605 signaling port 270

with Transport Layer Security (TLS) 605 full tunnel mode 61

full-tunnel mode 326

Fully-Qualified Domain Name (FQDN) 583

G

gateway policy. See VPN gateways. Generic Routing Encapsulation. See GRE.

global SSL setting 327 user portal logo 328

GRE 211

H

H.323 266

additional signaling port 270 and firewall 266

and RTP 266 signaling port 270

H.323. See also ALG. header checksum 433 host-based intrusions 417, 445

HTTP

redirect to HTTPS 590 vs HTTPS 588

HTTP Inspection 457

HTTP over SSL. See HTTPS.

HTTP redirect 261

and application patrol 261 and firewall 261

and interfaces 264 and policy routes 261 configuration overview 121 packet flow 261 prerequisites 121

HTTPS 588

and certificates 588

authenticating clients 588 avoiding warning messages 594 example 592

vs HTTP 588

with Internet Explorer 593 with Netscape Navigator 593

hub-and-spoke VPN. See VPN concentrator.

HyperText Transfer Protocol over Secure Socket Layer. See HTTPS.

I

ICMP 521 ICMP code 438 ICMP Decoder 457 ICMP echo 452 ICMP flood 452 ICMP portsweep 451

ICMP sequence number 438 ICMP type 438

ICMP unreachable 452 identification (IP) 437

IDP

action 427 alerts 426

and services 522

applying custom signatures 442 base profiles 421

bindings 419, 420 configuration overview 120 custom signature example 439 custom signatures 432

false negatives 423 false positives 423 inline profile 423 license status 158, 159 log options 426

packet inspection profiles 424 packet inspection signatures

signatures

packet inspection 424

policy types 427 prerequisites 120 profiles 418, 419 query view 426, 429 registration status 168, 420 reject sender 427 reject-both 427 reject-receiver 427 severity 426

signature ID 426 signatures

signatures

770

 

ZyWALL USG 1000 User’s Guide