Zyxel ZyWALL 1100 [71/327] What could go wrong

Zyxel USG 60 [71/327] What could go wrong
Chapter 3 Protect Your Network with UTM
ZyWALL/USG Series Handbook
71
2 Open the Nmap GUI, set the Target to be the WAN IP of ZyWALL/USG (172.124.163.150 in this
example) and set Profile to be Intense Scan. Click Scan.
Figure 117 Test in Zenmap
3 Go to the ZyWALL/USG Monitor > Log, you will see [warn] log message such as below.
Figure 118 Monitor > Log
3.4.3 What Could Go Wrong?
You may find that certain rules are triggering too many false positives or false negatives. A false
positive is when valid traffic is flagged as an attack. A false negative is when invalid traffic is
wrongly allowed to pass through the ZyWALL/USG. As each network is different, false positives and
false negatives are common on initial ADP deployment. You could create a new ‘monitor profile’
that creates logs but all actions are disabled. Observe the logs over time and try to eliminate the
causes of the false alarms. When you’re satisfied that they have been reduced to an acceptable
level, you could then create an ‘inline profile’ whereby you configure appropriate actions to be taken
when a packet matches a detection.

Содержание

Похожие устройства