Page 161 / 342 Scroll up to view Page 156 - 160
SmartDefense
Nokia IP45 Security Platform User’s Guide v4.0
161
2.
Click SmartDefense Wizard.
The SmartDefense wizard appears.
3.
Select the level of SmartDefense. Options are extra strict, high, normal and minimal.
4.
Click Next.
Application Intelligence Server Types window opens.
Page 162 / 342
8
Setting Up the Nokia IP45 Security Platform Security Policy
162
Nokia IP45 Security Platform User’s Guide v4.0
5.
Select the type of public servers you run/use on the network. Options are HTTP, FTP, CIFS
and other type of servers.
6.
Click Next.
The Application Blocking window opens.
7.
Select the type of applications that should be blocked in your network: peer-to-peer file
sharing, instant messengers and skype.
8.
Click Next.
The Confirmation window opens.
Page 163 / 342
SmartDefense
Nokia IP45 Security Platform User’s Guide v4.0
163
9.
SmartDefense rules are set and you can view a list of profiles that you selected.
10.
Click Finish to clear the existing settings and to apply the new settings.
Restoring Default Settings
You can also restore the default settings of SmartDefense.
To restore default settings
1.
From the main menu, choose Security > SmartDefense.
The SmartDefense page is displayed.
2.
Click Reset to Defaults.
The default settings are restored.
Configuring SmartDefense
You can handle the following by using SmartDefense.
±
Denial of Service
±
IP and ICMP
±
TCP
±
Port Scan
±
FTP
±
HTTP
±
Microsoft Networks
±
IGMP
±
Peer to Peer
±
Instant Messaging Traffic
Page 164 / 342
8
Setting Up the Nokia IP45 Security Platform Security Policy
164
Nokia IP45 Security Platform User’s Guide v4.0
Denial of Service
Denial of Service includes the following attacks:
±
TearDrop
—the attacker sends two IP fragments, the latter entirely contained within the
former. This causes some computers to allocate too much memory and crash.
±
Ping of Death
—in a Ping of Death Attack, the attacker sends a fragmented PING request
that exceeds the maximum IP packet size (64 KB). Some operating systems are unable to
handle such requests and crash.
±
LAND
— the attacker sends a SYN packet, in which the source address and port are the
same as the destination (the victim computer). The victim computer then tries to reply to
itself and either reboots or crashes.
±
Non-TCP Flooding
—advanced Firewalls maintain state information about connections in a
State table. In non-TCP Flooding attacks, the attacker sends high volumes of non-TCP
traffic. Since such traffic is connectionless, the related state information cannot be cleared or
reset, and the firewall State table is quickly filled up. This prevents the firewall from
accepting new connections and results in a Denial of Service (DoS).
±
DDoS Attack
—in a distributed denial-of-service attack (DDoS attack), the attacker directs
multiple hosts in a coordinated attack on a victim computer or network. The attacking hosts
send large amounts of spurious data to the victim, so that the victim is no longer able to
respond to legitimate service requests.
To handle teardrop attack
1.
From the main menu, choose Security > SmartDefense.
SmartDefense page is displayed.
SmartDefense GUI is organized as a tree structure in which each branch represents a
category of setting.
Page 165 / 342
SmartDefense
Nokia IP45 Security Platform User’s Guide v4.0
165
2.
Select Denial of Service to expand the tree view.
3.
Select Teardrop.
The teardrop configuration information appears in the SmartDefense configuration pane.
4.
Select the field values by using the information provided in
Table 31
.
5.
Click Apply.
The settings are saved.
6.
To store the default setting, click Default.
A confirmation message appears.
Click OK.
Table 31
Denial Of Service - fields for Teardrop, Ping of Death, LAND and DDoS
Field
Action
Action
Choose the action to be taken against the Denial of Service attacks.
Options:
Block: blocks the attack
None: no action is required
Default value: Block
Track
Specify whether to log the attacks.
Options:
Log: logs the attack
None: does not log the attack
Default value: Log

Rate

3.5 / 5 based on 2 votes.

Popular Nokia Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top