Geplaatst: 10 aug 2006, 17:14
Ik heb het IDS-verhaal vanmorgen eens bekeken. Het lijkt me dat het volstaat om dos-in (voor het blokkeren van gekende DOS-attacks van buitenaf) en spf-out (stateful packet filtering) aan te zetten voor de WAN interface. Hieronder is mijn configuratie. Heeft iemand andere instellingen gebruikt?
ATOS006015\IDS>>show conf
Show of ATOS006015 IDS test
Interface : ATM_VC0
Trace on alarm : on
ACL outgoing :
ACL ingoing :
Log level : 2
Show of ATOS006015 IDS test dos-in
Enable : on
Fragmentation : permitted
Detect ping of death : on
Fragment minimum length (byte) : 20
Fragment time out (sec) : 10
Source routing option : denied
Detect spoofing attack : on
Detect smurf attack : on
Detect fraggle attack : on
Detect land attack : on
Inspection protocol : off
Detect TCP flood : on
TCP flood max rate (packet/min) : 20
Detect UDP flood : on
UDP flood max rate (packet/min) : 20
Detect ICMP flood : on
ICMP flood max rate (packet/min) : 20
ICMP block time (sec) : 0
Detect sequence number error : off
Detect scan by TCP flags : on
TCP idle time (sec) : 120
UDP idle time (sec) : 30
ICMP idle time (sec) : 5
TCP final wait time (sec) : 5
Minimun packet length (byte) : 20
Show of ATOS006015 IDS test dos-out
Enable : off
Fragmentation : permitted
Detect ping of death : on
Fragment minimum length (byte) : 20
Fragment time out (sec) : 10
Source routing option : denied
Detect spoofing attack : on
Detect smurf attack : on
Detect fraggle attack : on
Detect land attack : on
Inspection protocol : off
Detect TCP flood : on
TCP flood max rate (packet/min) : 20
Detect UDP flood : on
UDP flood max rate (packet/min) : 20
Detect ICMP flood : on
ICMP flood max rate (packet/min) : 20
ICMP block time (sec) : 0
Detect sequence number error : off
Detect scan by TCP flags : on
TCP idle time (sec) : 120
UDP idle time (sec) : 30
ICMP idle time (sec) : 5
TCP final wait time (sec) : 5
Minimun packet length (byte) : 20
Show of ATOS006015 IDS test spf-out
Protocol / Idle time
tcp 30
udp 60
icmp 20
tftp 30
ftp 60
Show of ATOS006015 IDS test spf-in
No protocol defined
ATOS006015\IDS>>show conf
Show of ATOS006015 IDS test
Interface : ATM_VC0
Trace on alarm : on
ACL outgoing :
ACL ingoing :
Log level : 2
Show of ATOS006015 IDS test dos-in
Enable : on
Fragmentation : permitted
Detect ping of death : on
Fragment minimum length (byte) : 20
Fragment time out (sec) : 10
Source routing option : denied
Detect spoofing attack : on
Detect smurf attack : on
Detect fraggle attack : on
Detect land attack : on
Inspection protocol : off
Detect TCP flood : on
TCP flood max rate (packet/min) : 20
Detect UDP flood : on
UDP flood max rate (packet/min) : 20
Detect ICMP flood : on
ICMP flood max rate (packet/min) : 20
ICMP block time (sec) : 0
Detect sequence number error : off
Detect scan by TCP flags : on
TCP idle time (sec) : 120
UDP idle time (sec) : 30
ICMP idle time (sec) : 5
TCP final wait time (sec) : 5
Minimun packet length (byte) : 20
Show of ATOS006015 IDS test dos-out
Enable : off
Fragmentation : permitted
Detect ping of death : on
Fragment minimum length (byte) : 20
Fragment time out (sec) : 10
Source routing option : denied
Detect spoofing attack : on
Detect smurf attack : on
Detect fraggle attack : on
Detect land attack : on
Inspection protocol : off
Detect TCP flood : on
TCP flood max rate (packet/min) : 20
Detect UDP flood : on
UDP flood max rate (packet/min) : 20
Detect ICMP flood : on
ICMP flood max rate (packet/min) : 20
ICMP block time (sec) : 0
Detect sequence number error : off
Detect scan by TCP flags : on
TCP idle time (sec) : 120
UDP idle time (sec) : 30
ICMP idle time (sec) : 5
TCP final wait time (sec) : 5
Minimun packet length (byte) : 20
Show of ATOS006015 IDS test spf-out
Protocol / Idle time
tcp 30
udp 60
icmp 20
tftp 30
ftp 60
Show of ATOS006015 IDS test spf-in
No protocol defined