Symantec 360R Administration Guide - Page 204

IDS/IPS field descriptions

Page 204 highlights

204 Field descriptions IDS/IPS field descriptions Table C-31 Advanced tab field descriptions (Continued) Section Field Description Global IKE Settings (Phase 1 Rekey) SA Lifetime Time, in minutes, before phase 1 renegotiation of new encryption and authentication keys for the tunnel. The default value is 1080 minutes. The maximum value is 2,147,483,647 minutes. RADIUS Settings Primary RADIUS Server IP address or fully qualified domain name of the server used to process extended authentication exchanges with VPN clients. The maximum values is 128 alphanumeric characters. Secondary RADIUS Server IP address or fully qualified domain name of the alternate server used to process extended authentication exchanges with VPN clients. The maximum values is 128 alphanumeric characters. Authentication Port (UDP) Port on the RADIUS server used for authentication. The default value is 1812. The maximum value is 65535. Shared Secret or Key Authentication key used by the RADIUS server. The maximum value is 50 alphanumeric characters. IDS/IPS field descriptions The Symantec Gateway Security 300 series security gateway provides intrusion detection and prevention (IDS/IPS). The IDS/IPS functions are enabled by default, and provide atomic packet protection with spoof protection and IP. You may disable IDS/IPS functionality at any time. The following types of protection are offered with the IDS/IPS feature: ■ IP spoofing protection ■ IP options verification ■ TCP flag validation ■ Trojan horse protection

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

204
Field descriptions
IDS/IPS field descriptions
IDS/IPS field descriptions
The Symantec Gateway Security 300 series security gateway provides intrusion
detection and prevention (IDS/IPS). The IDS/IPS functions are enabled by
default, and provide atomic packet protection with spoof protection and IP. You
may disable IDS/IPS functionality at any time.
The following types of protection are offered with the IDS/IPS feature:
IP spoofing protection
IP options verification
TCP flag validation
Trojan horse protection
Global IKE
Settings (Phase 1
Rekey)
SA Lifetime
Time, in minutes, before phase 1 renegotiation
of new encryption and authentication keys for
the tunnel.
The default value is 1080 minutes. The
maximum value is 2,147,483,647 minutes.
RADIUS Settings
Primary RADIUS
Server
IP address or fully qualified domain name of the
server used to process extended authentication
exchanges with VPN clients.
The maximum values is 128 alphanumeric
characters.
Secondary
RADIUS Server
IP address or fully qualified domain name of the
alternate server used to process extended
authentication exchanges with VPN clients.
The maximum values is 128 alphanumeric
characters.
Authentication
Port (UDP)
Port on the RADIUS server used for
authentication.
The default value is 1812. The maximum value is
65535.
Shared Secret or
Key
Authentication key used by the RADIUS server.
The maximum value is 50 alphanumeric
characters.
Table C-31
Advanced tab field descriptions (Continued)
Section
Field
Description