ZyXEL ZYWALL USG 100 User Guide - Page 51

ADP Profile Configuration, 3.7.1 Procedure To Create a New ADP Profile

Page 51 highlights

Chapter 3 Protecting Your Network 3 Edit the default log options and actions. 3.7 ADP Profile Configuration ADP (Anomaly Detection and Prevention) protects against anomalies based on violations of protocol standards (RFCs - Requests for Comments) and abnormal traffic flows such as port scans. You may want to create a new profile if not all traffic or protocol rules in a base profile are applicable to your network. In this case you should disable non-applicable rules so as to improve ZyWALL ADP processing efficiency. You may also find that certain rules are triggering too many false positives or false negatives. A false positive is when valid traffic is flagged as an attack. A false negative is when invalid traffic is wrongly allowed to pass through the ZyWALL. As each network is different, false positives and false negatives are common on initial ADP deployment. You could create a new 'monitor profile' that creates logs but all actions are disabled. Observe the logs over time and try to eliminate the causes of the false alarms. When you're satisfied that they have been reduced to an acceptable level, you could then create an 'inline profile' whereby you configure appropriate actions to be taken when a packet matches a detection. 3.7.1 Procedure To Create a New ADP Profile To create a new profile: ZyWALL USG100-PLUS User's Guide 51

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 3 Protecting Your Network
ZyWALL USG100-PLUS User’s Guide
51
3
Edit the default log options and actions.
3.7
ADP Profile Configuration
ADP (Anomaly Detection and Prevention) protects against anomalies based on violations of protocol
standards (RFCs – Requests for Comments) and abnormal traffic flows such as port scans.
You may want to create a new profile if not all traffic or protocol rules in a base profile are
applicable to your network. In this case you should disable non-applicable rules so as to improve
ZyWALL ADP processing efficiency.
You may also find that certain rules are triggering too many false positives or false negatives. A
false positive is when valid traffic is flagged as an attack. A false negative is when invalid traffic is
wrongly allowed to pass through the ZyWALL. As each network is different, false positives and false
negatives are common on initial ADP deployment.
You could create a new ‘monitor profile’ that creates logs but all actions are disabled. Observe the
logs over time and try to eliminate the causes of the false alarms. When you’re satisfied that they
have been reduced to an acceptable level, you could then create an ‘inline profile’ whereby you
configure appropriate actions to be taken when a packet matches a detection.
3.7.1
Procedure To Create a New ADP Profile
To create a new profile: